Trust

Security at Cliff

Manufacturers trust Cliff with decades of product knowledge. We protect that trust with enterprise-grade controls, transparent practices, and an architecture designed for tenant isolation from day one.

Encryption everywhere

Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Keys are managed in a hardware-backed KMS with strict rotation policies.

Identity & access

SSO via SAML 2.0 and OIDC, SCIM provisioning, role-based access controls, and enforced MFA for all Cliff staff with production access.

Tenant isolation

Each customer's content lives in a logically isolated namespace. Retrieval indexes are scoped per tenant — no cross-tenant data ever touches a model context.

Compliance

SOC 2 Type II audited annually. GDPR and CCPA aligned. HIPAA available on Enterprise. Subprocessor list and DPAs available on request.

Model privacy

We use enterprise model endpoints under zero-retention agreements. Your content is never used to train shared or third-party models.

Vulnerability management

Continuous dependency scanning, quarterly third-party penetration testing, and a coordinated disclosure program at security@cliff.ai.

Reporting a vulnerability

Reporting a vulnerability

We welcome reports from the security community. Please email security@cliff.ai with details and steps to reproduce.

Status & uptime

Status & uptime

We target 99.9% monthly uptime for the Service. Real-time status is published at status.cliff.ai with historical incident reports.

Documentation

Documentation

SOC 2 reports, penetration test summaries, DPAs, and our subprocessor list are available under NDA. Contact trust@cliff.ai.

© 2026 Cliff AI · A Sparkfive product