Security & trust

Real controls, not a promise.

Before you move a whole team’s mail somewhere, you should be able to see exactly what’s protecting it. Here’s what’s actually shipped — not a roadmap.

Access & accountability

What you can see and control today

1

Session tracking, with real revocation

Every sign-in creates a tracked session, tied to a device. See exactly what's signed in to your workspace right now, and revoke any one of them instantly — without changing your password.

2

A full audit log

Every admin action — removing a user, disconnecting a domain, changing a policy — is written to an audit log with who did it and when. Nothing important happens silently.

3

Scoped API keys

Connect integrations through API keys you issue and can revoke individually, instead of sharing account credentials with a third-party tool.

4

Verified domain ownership

Connecting a domain requires DNS verification before Clario will send or receive mail on it — nobody can claim a domain they don't control.

Data handling

How your data is actually treated

Passwords are hashed, never stored in plain text. Session tokens are hashed on the server; only a signed cookie holds the raw value, the same pattern used for password-reset links.

Your mail content is sent to Clario's AI provider only to generate the specific draft, summary, or answer you asked for — never to train a model.

Every mailbox and domain is scoped to your workspace. There's no cross-tenant visibility between businesses on Clario.

Have a security or compliance question we haven’t answered?

We’d rather answer it directly than have you guess.