Security
Security Through Experience
Clario is a product that is being built securely from the ground up. Team members have experience in both internal security and compliance functions at numerous tech companies, additionally team members have worked at a number of key cybersecurity companies building products to broadly secure a wide variety of companies and organizations.
By understanding through experience core tenants of Clario design include role based access, principal of least privilege and operational transparency for customers.
Data Transport
Clario serves HSTS headers and participates in the HSTS preload list used by major browser vendors. The Clario application does not accept plain TCP connections or TLS connections with clients using TLS versions below 1.2, and achieves an A+ rating from the Qualys SSL Labs toolbox.
Credentials & Authentication
Clario Internal Authentication
Clario-internal users are required to authenticate to applications and infrastructure using SSO through an integration with Clario’s Okta instance. Clario enforces periodic reauthentication and mandatory use of multi-factor authentication.
Clario External Authentication
Customer Authentication is configured to operate through Google or Microsoft account based OAuth authentication. Security enforcement such as multi-factor authentication applied to these accounts by an upstream IdP provides additional protection.
Login attempts using this system are rate-limited. All authentication requests are logged within the Clario platform. Session lengths and idle time outs can be set in the administration panel with a maximum length of 12 hour sessions and 30 minute idle time out.
Customer Credentials & API Tokens
Clario does not store customer credentials with our systems. Authentication with customer systems is validated using secured API token based authentication. Tokens are stored encrypted at rest and in-transit and only stored when required. Access to these credentials inside the Clario application is gated by a role-based access control system to ensure that only those processes that have a confirmed business need may use them, and any access via the Clario application is logged. Clario has a policy of only accepting and storing customer tokens that are limited in scope by the principle of least privilege.
Data Storage
Primary datastores are encrypted at rest, and are not used to store any information considered an application secret (e.g., database passwords or API keys). The relational database is regularly backed up, and we have a data restoration plan that has been tested in production.
Clario explicitly only accesses and reviews customer filesystems metadata and never file content. This means that your files are not open or read by Clario systems.
Logging
Clario's application is deployed in Google Cloud Platform (GCP) and utilizes Google Cloud Observability Suite. Cloud Logging serves as its primary log sink, and Cloud Monitoring is used for reporting and analysis.
Security Review
Clario has undertaken third-party security reviews of our application, deployment practices, Infrastructure security and configuration, and corporate security practices. Clario has a policy of prioritizing any high-severity findings that arise from these reviews.
Additionally, Clario has a policy of requiring internal security-specialist review of our systems on at minimum a quarterly basis. This includes any code changes affecting key security considerations, including changes to our authentication or authorization models. This security-specialist code review is in addition to our standard code review and continuous integration test suite requirements.
Corporate Security
Clario has a vendor security evaluation process for new systems and sub processors to determine the security posture and validity of a particular vendor. This review determines inclusion represents a reasonable decision from a risk management perspective. Reviews are conducted at renewal to determine the nature of any material changes to a vendor’s posture or suitability.
Wherever possible, Clario configures Single Sign-On with its SaaS vendors, either directly via Okta, or delegated through Google Workspace OAuth based authentication.
Clario has an employee lifecycle process that ensures offboarded employees no longer have access to sensitive information or systems they used as part of their role at Clario.
Incident Response
Clario has and follows a written process for managing security incidents, including security incidents related to vulnerabilities that have no evidence of active exploitation.
Related Links
For Security and Compliance documentation please visit the Clario Trust Center
For current Product Status and updates please visit the Clario Status Page