Cybersecurity Policy

Clau – Personal Finance & AI Assistant

Effective Date: April 22, 2026  |  Operated by Vivytech  |  support@clau.app

This Cybersecurity Policy describes the technical and organizational controls Vivytech has implemented to protect user data and maintain the security of the Clau platform. This policy is provided in connection with Alpaca Markets' OAuth due diligence requirements and is publicly available for transparency.

1. Data Classification

Vivytech classifies data into three tiers, each with corresponding handling requirements:

Tier Examples Controls
Highly Sensitive Alpaca OAuth tokens, Stripe credentials, JWT refresh tokens, passwords Encrypted at rest (Fernet / AES-256); never logged; access restricted to backend service only
Sensitive Full name, email, phone, bank balances, portfolio data, AI messages Stored in PostgreSQL with access restricted to authenticated API calls; encrypted in transit (TLS); JWT access token required
Internal Gamification points, notification preferences, AI message count, FCM tokens Stored in PostgreSQL; authenticated API access required; not surfaced publicly

2. Authentication and Access Control

User Authentication

API Access Control

Infrastructure Access

3. Encryption

In Transit

At Rest — Server Side

At Rest — Client Side (Android)

4. Third-Party Vendor Security

Vendor Purpose Security Posture
Amazon Web Services Server infrastructure (EC2, networking) SOC 2 Type II, ISO 27001, PCI DSS Level 1 certified. Vivytech manages OS-level security and access controls on top of AWS's shared responsibility model.
Stripe, Inc. Payment processing, bank data aggregation PCI DSS Level 1 Service Provider. Stripe handles all cardholder data; Vivytech never processes raw card numbers.
Alpaca Securities LLC Brokerage / trading execution FINRA-registered broker-dealer, SIPC member. OAuth 2.0 authorization with short-lived encrypted tokens. Tokens revocable by user at any time.
Google LLC (Firebase) Push notifications ISO 27001, SOC 2, SOC 3 certified. Only device FCM tokens are shared — no financial data.
Google LLC (Gemini AI) AI inference Enterprise API with data processing agreements available. User AI messages and financial context are transmitted over HTTPS and subject to Google's API data handling policies.
PostgreSQL Primary data store Self-managed on AWS EC2. Database not internet-exposed. Regular automated backups.

5. Vulnerability Management

6. Incident Response

Detection

Response Plan

Data Backup and Recovery

7. Physical and Organizational Security

8. Contact for Security Issues

To report a security vulnerability or suspected data breach, please contact us immediately: