Find answers about security
How does Clerked separate company data?
Clerked enforces tenant boundaries in PostgreSQL with row-level security. Requests carry the active company and user context, and application permission checks control the requested action.
This is a system control, so customer data separation does not depend only on a screen filter.
How is sign-in protected?
Clerked uses AWS Cognito for authentication. The web application uses a signed session token in an HTTP-only cookie, which means browser scripts cannot read the token.
Where are connector credentials kept?
Clerked stores infrastructure and connector secrets in AWS Secrets Manager instead of putting them in the browser or local storage.
Do not send passwords, access tokens, or secret keys in an ordinary support message. Follow the secure credential process supplied by your Clerked contact.
How do I ask about AI training, storage region, or retention?
These answers can depend on your contract and company setup. Contact your Clerked contact or support@clerked.ai for the terms that apply to your company.
What should I include in a security request?
Include your company name, the requirement or questionnaire item, and any response deadline. Do not include passwords, access tokens, or secret keys.