Back to home

Security at Clawler

Your keys, your data, your control. Here's exactly how we protect them.

🔐Your Keys Are Safe

🔐

Encrypted at Rest

All API keys are encrypted using AES-256-GCM before storage. Even in a database breach, your keys are useless without our encryption key.

🚫

Never Logged

API keys never appear in server logs, error reports, or analytics. We mask keys everywhere they're displayed.

🔑

Used Only When You Call

Keys are only decrypted in-memory at the moment you initiate a voice session. They're never cached or kept in memory after your call ends.

🌐

Gemini Stays Client-Side

Your Gemini voice key connects directly from your browser to Google. It never passes through our servers.

💬Your Conversations Are Private

💬

No Server-Side Logging

Voice transcripts and screen share data are processed in real-time and not stored on our servers.

🖥️

Screen Data is Ephemeral

Screen share content is analyzed in the moment and immediately discarded. We never save screenshots or recordings.

🔒

TLS Everywhere

All data in transit is encrypted via TLS 1.3.

👤Your Account, Your Control

🗑️

Delete Anytime

Delete your account and all associated data is immediately and permanently purged. Keys, sessions, everything.

🔄

Rotate Keys Freely

Update or remove your API keys at any time from Settings.

👁️

No Tracking

No third-party analytics, no ad trackers, no cookies beyond essential session management.

🏗️Infrastructure

☁️

Hosted on Vercel (SOC 2 Type II compliant)

🔐

Database encryption at rest

🛡️

Regular security reviews

🔒

HTTPS only — HTTP requests are automatically redirected

Questions?

If you have security concerns or want to report a vulnerability, email security@clawler.ai