How we protect your data
Your contracts contain some of the most sensitive information in your business. Here's exactly what we do to protect them.
Last updated: September 11, 2026
Encryption in transit and at rest
All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher. Data stored in our database is encrypted at rest. Contract files uploaded for analysis are processed in memory and not written to permanent storage.
Row-level access control
Every database table is protected by Row Level Security (RLS). Users can only read and write their own data — there is no query path that allows one customer to access another's contracts, alerts, or account information. This is enforced at the database level, not just the application layer.
Authentication
ClausePulse uses magic-link email authentication — no passwords to guess, phish, or reuse. Login links are single-use and expire after 60 minutes. All authenticated sessions are scoped and cannot be transferred between users.
Contract files are not retained
Files you upload for analysis are processed to extract renewal dates, notice windows, and key terms — then discarded. We do not store your raw contract documents in our systems after analysis is complete. Extracted structured data (dates, vendor name, contract value) is stored in your account and accessible only to you.
AI processing policy
Contract analysis is powered by OpenAI's API. We use the API as a data processor — OpenAI does not use API inputs to train their models. Your contract content is sent for analysis and is not stored by OpenAI beyond the duration of the request. See OpenAI's enterprise privacy policy for details.
Infrastructure
ClausePulse runs on enterprise-grade cloud infrastructure with automated backups, uptime monitoring, and isolated tenant environments. Our backend and database are hosted in the United States. We do not host data in jurisdictions with inadequate privacy protections.
Report a vulnerability
If you discover a security issue, please report it responsibly to legal@clausepulse.com. We will acknowledge receipt within 2 business days and work to resolve confirmed issues promptly. We ask that you do not publicly disclose the issue until we've had a chance to address it.