Claervo for monday.com

Security overview

A practical summary of the controls protecting tenant access, credentials and governance evidence.

01

Least privilege

Claervo uses documented read permissions and does not request board mutation scopes. Visibility follows the authorizing administrator's existing monday.com access.

02

Credential protection

OAuth credentials are encrypted using AES-256-GCM with rotation-ready keys. Sessions use signed, HTTP-only cookies and OAuth uses PKCE and signed state.

03

Tenant isolation

Every durable domain record is tenant-scoped. Sensitive routes and server actions re-check authentication, tenant authority and role requirements.

04

Operational safeguards

Controls include CSP, endpoint rate limiting, lifecycle webhook verification, redacted logs, dependency scanning, audit records, tested deletion workflows and environment-secret separation.

05

Responsible disclosure

Send suspected vulnerabilities privately to support@claervo.com with impact and safe reproduction steps. Do not include live credentials or disclose the report publicly before coordination.