Trust
Security at Cliff
Manufacturers trust Cliff with decades of product knowledge. We protect that trust with enterprise-grade controls, transparent practices, and an architecture designed for tenant isolation from day one.
Encryption everywhere
Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Keys are managed in a hardware-backed KMS with strict rotation policies.
Identity & access
SSO via SAML 2.0 and OIDC, SCIM provisioning, role-based access controls, and enforced MFA for all Cliff staff with production access.
Tenant isolation
Each customer's content lives in a logically isolated namespace. Retrieval indexes are scoped per tenant — no cross-tenant data ever touches a model context.
Compliance
SOC 2 Type II audited annually. GDPR and CCPA aligned. HIPAA available on Enterprise. Subprocessor list and DPAs available on request.
Model privacy
We use enterprise model endpoints under zero-retention agreements. Your content is never used to train shared or third-party models.
Vulnerability management
Continuous dependency scanning, quarterly third-party penetration testing, and a coordinated disclosure program at security@cliff.ai.
We welcome reports from the security community. Please email security@cliff.ai with details and steps to reproduce.
We target 99.9% monthly uptime for the Service. Real-time status is published at status.cliff.ai with historical incident reports.
SOC 2 reports, penetration test summaries, DPAs, and our subprocessor list are available under NDA. Contact trust@cliff.ai.

