CLOCOT SECURITY & DATA RETENTION POLICY
Effective Date: October 2, 2026 Last Updated: October 2, 2026
This Policy describes high-level security and data-retention practices used to protect Clocot and Customer data. It is intentionally written at a level that provides transparency without publishing operational details that could weaken security.
1. SECURITY PROGRAM
LexLupi maintains a security program designed to protect the confidentiality, integrity, availability, and appropriate isolation of Clocot systems and data.
Security controls evolve as the platform, infrastructure, threat environment, and legal requirements change.
2. SHARED RESPONSIBILITY
Security is a shared responsibility.
LexLupi is responsible for security of the Clocot platform within its control.
Customers are responsible for account credentials, administrator permissions, devices, connected services, user access, API keys they provide, lawful data handling, endpoint security, and configuration choices.
3. TENANT ISOLATION
Clocot is designed as a multi-tenant system with controls intended to prevent one tenant from accessing another tenant's protected records.
Database and application controls may include tenant-scoped authorization, row-level security, role checks, and service-layer validation.
4. DATABASE PRIVILEGE SEPARATION
Where supported by the deployment, migration or administrative database privileges are separated from runtime application privileges.
Runtime applications are designed to use restricted database roles rather than unrestricted administrative credentials.
5. AUTHENTICATION
Clocot may use passwords, magic links, session tokens, multi-factor authentication, passkeys, social or enterprise sign-in, recovery codes, and other authentication methods.
Available methods depend on product stage and account configuration.
6. PASSWORD AND TOKEN PROTECTION
Authentication secrets are not intended to be stored in plaintext.
Security measures may include hashing, encryption, token expiration, rotation, and revocation.
7. MULTI-FACTOR AUTHENTICATION
Clocot may provide multi-factor authentication and passkey functionality.
Administrators should enable strong authentication for privileged accounts where available.
8. API KEY AND OAUTH TOKEN SECURITY
Customer-provided API keys, OAuth tokens, and provider credentials are treated as sensitive security data.
Clocot is designed to encrypt stored provider credentials and separate credential domains where technically appropriate.
Customers should revoke credentials that may have been exposed.
9. ENCRYPTION IN TRANSIT
Clocot uses encrypted transport protocols, such as HTTPS/TLS, for supported production traffic.
Third-party integrations depend on the transport security offered by the relevant provider.
10. ENCRYPTION AT REST
Production infrastructure may use encryption at rest provided by the relevant database, storage, hosting, or cloud service.
Highly sensitive application secrets may also use application-level encryption.
11. ACCESS CONTROL
Internal access to production systems is limited according to operational need and authorization.
Where appropriate, access controls may include role-based permissions, least privilege, separate administrative functions, environment restrictions, and audit logging.
12. LOGGING AND AUDIT TRAILS
Clocot may log security-relevant events such as sign-in, failed authentication, privilege changes, administrative actions, integration changes, workflow events, account recovery, security alerts, and system errors.
Logs are used for security, troubleshooting, fraud prevention, and operational integrity.
13. SECRET SCANNING AND SOFTWARE SECURITY
Clocot development practices may include secret scanning, dependency review, code review, automated tests, security tests, environment separation, typed configuration, and secure coding controls.
No development process eliminates all vulnerabilities.
14. VULNERABILITY MANAGEMENT
We may identify and remediate vulnerabilities through dependency updates, code changes, infrastructure updates, provider advisories, monitoring, internal testing, and responsible vulnerability reports.
Remediation priority depends on risk and exploitability.
15. RATE LIMITING AND ABUSE PROTECTION
Clocot may use rate limits, quotas, circuit breakers, abuse detection, access throttling, fraud controls, and feature restrictions to reduce misuse and service disruption.
16. BACKUPS
Production data may be backed up or replicated for resilience and disaster recovery.
Backup design depends on the relevant provider and workload.
Backups are protected from ordinary user access and are retained only for operationally appropriate periods.
17. BUSINESS CONTINUITY
We design Clocot to support recovery from infrastructure, software, provider, or operational failures.
Recovery objectives may vary by service and plan.
We do not guarantee uninterrupted service.
18. INCIDENT RESPONSE
LexLupi maintains processes for identifying, assessing, containing, remediating, and documenting significant security incidents.
Incidents may involve coordination with infrastructure providers, AI Providers, payment processors, integration providers, customers, or authorities.
19. BREACH NOTIFICATION
If a security incident triggers a legal duty to notify customers, individuals, regulators, or other parties, LexLupi will provide notice within the period required by applicable law.
Where LexLupi acts as a processor, processor-to-controller notice is governed by the DPA.
20. CUSTOMER SECURITY RESPONSIBILITIES
Customers should use strong authentication, limit administrator access, remove former users, protect API keys, review integrations, use least-privilege permissions, verify automation rules, secure devices, and report suspected compromise promptly.
21. RETENTION PRINCIPLES
We retain personal information and Customer data only for periods reasonably necessary for providing Services, customer instructions, legal compliance, accounting, security, fraud prevention, dispute resolution, contractual obligations, and business continuity.
Retention varies by category and feature.
22. ACCOUNT DATA RETENTION
Account and organization information is generally retained while the account is active and for a reasonable period after closure where necessary for security, fraud prevention, legal claims, billing, or statutory records.
23. CUSTOMER CONTENT RETENTION
Customer Content is retained according to account status, customer settings, workspace configuration, feature design, contract, legal requirements, and deletion requests.
Business customers may have different retention obligations for their own records.
24. AI CONVERSATION AND MEMORY RETENTION
AI conversations, workflow context, and Office Brain memory may persist where the feature is designed to maintain continuity.
Users or administrators may have tools to delete or change that information.
Derived or cached copies may require a reasonable technical period to synchronize after deletion.
25. SECURITY LOG RETENTION
Security and audit logs may be retained longer than ordinary content where reasonably necessary to investigate incidents, detect fraud, preserve evidence, defend claims, review access, and meet legal or compliance requirements.
26. BILLING AND TAX RECORDS
Invoices, transaction records, refund records, and tax information may be retained for statutory accounting, tax, fraud, and audit periods.
27. DELETION
When a valid deletion instruction applies, LexLupi will delete or de-identify applicable information from active systems within a reasonable operational period, subject to legal and technical exceptions.
Deletion may not be instantaneous across all distributed systems.
28. BACKUP RETENTION AFTER DELETION
Deleted information may remain temporarily in encrypted or protected backups until backups are rotated, overwritten, or expire.
Backup data is not intended to be restored for ordinary production use after deletion.
29. LEGAL HOLDS AND REQUIRED RETENTION
We may suspend deletion where information must be retained for litigation, regulatory inquiry, tax law, fraud prevention, law enforcement, contractual dispute, or another legal obligation.
Access to retained data remains limited.
30. CONTACT
Security concerns should be sent to office@clocot.com.
Do not include passwords, complete payment-card numbers, or unnecessary sensitive data in an initial report.
LexLupi LLC Legal Contact: Tatjana Sindjelic