Claervo for monday.com
Security overview
A practical summary of the controls protecting tenant access, credentials and governance evidence.
Least privilege
Claervo uses documented read permissions and does not request board mutation scopes. Visibility follows the authorizing administrator's existing monday.com access.
Credential protection
OAuth credentials are encrypted using AES-256-GCM with rotation-ready keys. Sessions use signed, HTTP-only cookies and OAuth uses PKCE and signed state.
Tenant isolation
Every durable domain record is tenant-scoped. Sensitive routes and server actions re-check authentication, tenant authority and role requirements.
Operational safeguards
Controls include CSP, endpoint rate limiting, lifecycle webhook verification, redacted logs, dependency scanning, audit records, tested deletion workflows and environment-secret separation.
Responsible disclosure
Send suspected vulnerabilities privately to support@claervo.com with impact and safe reproduction steps. Do not include live credentials or disclose the report publicly before coordination.
