Security

Clasper is built for regulated environments and audit-intensive workloads. Security is not a feature — it's the architecture.

Security Principles

Tenant Isolation

Every read and write is scoped by user_id from the agent token. Cross-tenant access is architecturally impossible.

Stateless by Design

No persistent sessions, no stored credentials, no agent memory. Your backend remains the source of truth.

Full Auditability

Immutable audit logs for all actions. Every agent decision is traceable, replayable, and explainable.

No Implicit Access

Agents operate through explicit API contracts. No shell access, no filesystem, no browser automation.

Data Handling

PII Redaction

Configurable patterns automatically redact sensitive data from traces and logs.

Retention Policies

Per-tenant retention controls with automatic cleanup enforcement.

RBAC Enforcement

Action-level permissions with enforced scopes. Non-admin users never see raw prompts or tool payloads.

Responsible Disclosure

We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly.

Report a vulnerability

[email protected]

We aim to acknowledge reports within 48 hours and provide a detailed response within 7 days.