Security at Clerai

Built for firms that take privacy seriously.

We handle your clients' books, so security isn't a feature: it's the product.

Published by the Clerai Security Operations Team • Last updated: July 9, 2026
Encrypted in transit and at rest

All data moves over TLS 1.2 or higher. Everything stored in the database is encrypted at rest with AES-256, and client receipts are stored in isolated private buckets with no public URLs.

Every row scoped to your firm

Postgres row-level security enforces that every row in the database is scoped to your firm, at the database layer, not just in application code.

OAuth only, bank logins never stored

Clerai connects to your ledger through OAuth. Your bank username and password are never requested and never stored.

Client links cannot be guessed

The magic links your clients use to answer questions are signed, single-use, and expire automatically after 30 days. They cannot be enumerated or guessed by anyone who doesn't hold the original link.

Every action is logged

Every categorization, approval, client answer, and sign-off is recorded in a full audit log you can export.

Your data, on request

Export or delete your firm's data on request. Found a security issue? Email security@clerai.app, our responsible disclosure address.

Responsible disclosure

Found something? Email security@clerai.app. We respond within one business day and don't pursue good-faith research.

See also Privacy, Terms, and Refund Policy.