Security at Clerai

Built for firms that take privacy seriously.

We handle your clients' books, so security isn't a feature: it's the product.

Published by the Clerai Security Operations Team • Last updated: July 9, 2026
How does Clerai encrypt financial data?

Clerai uses industry-standard TLS 1.2+ encryption for all data in transit. Database storage is protected using AES-256 encryption at rest, and all client receipts are stored in isolated private buckets without public URLs.

How is tenant data isolated?

Clerai enforces strict tenant isolation using row-level security (RLS) policies at the database layer. This ensures that every table is isolated so users can only view data matching their authorized firm profile.

Does Clerai store bank login details?

Clerai never requests or stores online-banking passwords or usernames. Clerai integrates using read-only QuickBooks Online OAuth protocols or imports transaction logs from standard CSV files.

Are client magic links secure?

Client questionnaire magic links use single-use, cryptographically signed tokens that expire automatically after 30 days. These tokens are highly secure and cannot be guessed or enumerated by third parties.

Is there an immutable audit trail?

Yes, Clerai automatically compiles a comprehensive audit trail logging every transaction approval, client communication, sign-off, and export with precise user-agent mapping and timestamp details.

Can firms export or delete data?

Firm administrators can export all transactions, categorizations, and receipts as standard CSV files at any time, or permanently purge their entire firm's databases and profile logs directly from Settings.

Responsible disclosure

Found something? Email security@clerai.app. We respond within one business day and don't pursue good-faith research.

See also Privacy, Terms, and Refund Policy.