Trust Center
Built for teams whose customers read the DPA.
Clynto handles your most sensitive commercial data - contracts, renewal terms, stakeholder relationships. Security is architecture, not a checkbox.
Hosted on Microsoft Azure
Clynto runs on Azure Container Apps with secrets managed in Azure Key Vault and traffic routed through Azure Front Door, hosted in United States regions. Deployments run through GitHub Actions using federated credentials - no long-lived cloud keys anywhere in the pipeline.
Your data never touches another customer’s
Every record is scoped to your organisation at the database layer through a mandatory tenant-scoping wrapper. Cross-tenant access is architecturally impossible, not just policy-prohibited.
Encrypted in transit, at rest, and at the field level
All traffic is TLS-encrypted. Data at rest is encrypted by default. Sensitive contract fields - pricing, renewal terms, commercial notes - receive an additional layer of field-level encryption so that even a full database read exposes nothing useful.
Least privilege by default
Five roles, plus 35 granular permission keys that can be granted or revoked per person - so you can let one CSM approve agent actions without making them a manager. A CSM sees only the accounts assigned to them. The read-only viewer role cannot be granted a write permission even by an override: turning a read-only account into a writing one is a role change, deliberately, not a checkbox. Integrations connect read-only unless you explicitly enable write-back.
Two-factor, and a list of every signed-in device
Optional TOTP two-factor through any authenticator app, with eight one-time recovery codes. Nothing is switched on until you have entered a working code, so a badly scanned QR cannot lock you out. Turning it off needs your password and a current code. Every browser you have signed in from is listed with its last-used time, and can be signed out individually; changing your password ends every other session.
Your data is never used to train shared models
Clynto uses enterprise AI deployments within its own cloud tenancy. Your account data is used only to serve your organisation and is never used to train models shared with other customers.
SOC 2-aligned controls
Clynto operates against an 80-item internal control framework aligned to SOC 2 principles. A completed vendor security questionnaire and Data Processing Agreement are available to prospects on request.
You own your data
Export at any time. On termination, all customer data is deleted within [30] days and a deletion confirmation is provided.