Back to Home
Trust & Governance

Security Overview

How we protect customer data, secure commercial transactions, and maintain resilient platform infrastructure.

Last reviewed: September 2026

Data Protection & Encryption

All network communication across our services is encrypted in transit using modern Transport Layer Security (TLS 1.3) with HTTP Strict Transport Security (HSTS) enforced across all platform domains. Persistent storage volumes, database partitions, and automated backups are encrypted at rest using industry-standard AES-256 encryption.

Multi-tenant organizational data is governed by strict logical boundaries enforced at the query layer. Access control policies ensure customer records, event configurations, and administrative tooling remain isolated and accessible only to authorized operators.

Payment Processing & PCI-DSS Compliance

Cardholder payment processing is handled directly by Tier-1 PCI-DSS certified payment partners (Stripe and PayPal) via client-side tokenization.

Raw payment card numbers, CVVs, and cardholder banking credentials are never handled, processed, or stored on our application servers. All financial transactions settle directly through regulated merchant acquiring networks.

Authentication & Session Security

User credentials are protected using salted cryptographic hashing algorithms. We never store, transmit, or log plaintext passwords under any circumstances.

Authenticated sessions rely on cryptographically signed session tokens transported through secure, HTTP-only browser cookies with cross-site request forgery defenses. Granular role-based access control (RBAC) enforces principle-of-least-privilege boundaries across attendee, organizer, and platform administrative tiers.

Infrastructure & Service Availability

The platform is hosted on geographically distributed edge infrastructure equipped with automated denial-of-service (DDoS) mitigation, edge firewall filtering, and automated bot deterrence during high-volume event registration peaks.

Production databases undergo automated continuous snapshots with point-in-time recovery, maintained in isolated secondary storage regions to ensure service continuity and data resilience.

Responsible Vulnerability Disclosure

We appreciate the contributions of security researchers and ethical hackers in keeping our community safe. If you believe you have discovered a potential security or privacy vulnerability, please report it to us responsibly.

Reporting Channel

Please send a detailed description of your findings to: security@clov.co

Please include reproducible steps, affected endpoints, and any relevant technical proof-of-concept material.

Safe Harbor Guidelines

We commit not to pursue legal action against security researchers who:

  • Conduct research and disclosure in good faith without degrading platform performance or availability.
  • Refrain from accessing, modifying, or exfiltrating data belonging to other users or organizations.
  • Provide our security team a reasonable period to investigate and remediate the issue prior to public disclosure.