Security

Last updated: July 30, 2026

Clariva holds your customer list, your pricing and your order history. This page describes how that data is protected. If your security team needs detail beyond this, email support@caringconsulting.co.

Hosting and encryption

  • Clariva runs on Google Cloud Platform in US regions.
  • All traffic to and from the application is encrypted in transit over HTTPS.
  • Data is encrypted at rest by the underlying Google Cloud storage services.
  • The application sends strict transport security and content security policy headers, and cookies are HTTP-only and secure.

Tenant isolation

Clariva is multi-tenant: each customer organization is a separate tenant, and every record is stored under that tenant. The tenant a request belongs to is taken from the signed-in user's verified identity token — never from anything the browser can set — so a user cannot reach another organization's data by changing a URL or a request body.

Access control

  • Role-based permissions decide what each user can see and do, down to individual capabilities.
  • Your administrators grant and revoke access themselves, and can adjust individual permissions per user.
  • Cost and margin visibility is a separate permission, so counter and service staff can work orders without seeing what you paid.
  • Sensitive actions require re-authentication at the moment you perform them, not just at sign-in.

Authentication

  • Passkeys (WebAuthn) and multi-factor authentication are supported, and administrators can require MFA.
  • Web sessions have an absolute lifetime and lock on inactivity, so an unattended browser does not stay open.
  • Administrators can disable a departing user and revoke their active sessions immediately.

Payment data

Card details are entered directly into payment fields hosted by Stripe, a PCI DSS Level 1 service provider. Card numbers do not pass through Clariva's servers, and Clariva never receives or stores a full card number, CVC or magnetic-stripe data. We store only the non-sensitive result of a payment — brand, last four digits and the processor's reference — so you can reconcile it.

Where you accept payments from your own customers, funds settle into your own account with the processor. Clariva does not hold or move your money.

Auditability

Security-relevant actions — permission changes, sign-ins, administrative changes and financial transitions — are written to an append-only audit log scoped to your tenant, with the acting user and timestamp.

Backups and availability

Data is stored in managed Google Cloud services with their built-in redundancy and point-in-time recovery. We do not currently publish a contractual uptime guarantee; see our Terms of Service for what we do commit to.

Sub-processors

We use a small number of vendors to deliver the service. They are named, with what each one does, on our sub-processor page.

Reporting a vulnerability

If you believe you have found a security issue, email support@caringconsulting.co with the detail needed to reproduce it. We will acknowledge within one business day. Please give us a reasonable opportunity to fix an issue before disclosing it publicly, and do not access or modify data that is not yours while testing.