Trust

Security at cleap

Connecting a repository means handing over the most sensitive thing your company owns. This page is what we do about that, in enough detail to check. For what cleap takes and keeps, read how cleap handles your code.

Read-only
GitHub access
7
companies named
3 days
to answer a report

One direction. The GitHub permission has no write scope. Writing back is not possible, not just declined.

Your workspace only. Access is decided by the database on every read, not by the screen you are looking at.

Credentials are never readable. API keys are stored as hashes. A database you connect is encrypted with its own key.

We say what is missing. Section 8 is the list of things we have not done yet.

1. Where your code goes

One way in, and nothing goes back.

YOURSOURSWHO SEES ITYour repositoryread-only accessyou grant, and revokereadscleapkeeps the structure: files, symbols,connections. Not a copy of the code.the mapYour teamyour workspace onlyClaudea slice, only when you asknothing is ever written back to your repositoryopen a file and it is fetched from GitHub right then, and not saved here
One direction, by design. The permission cleap asks GitHub for has no write scope, so writing back is not something we choose not to do. It is something we cannot do.

You grant access on GitHub's own screen, for every repository or only the ones you pick, and you can change or revoke it there at any time without asking us. Reads use a short-lived token scoped to that one grant, so cleap holds no standing access to your account.

2. Who can reach your map

People in your workspace, and nobody else, decided by the database itself.

Every table carries a rule about who may read or change each row, and those rules run inside Postgres on every query. This matters more than it sounds: the check is not in the page you are looking at, so a bug in our interface, or a request made without one at all, still cannot return another workspace's rows.

Within a workspace, roles decide the rest. Owners and admins manage people and billing, editors can annotate a map, viewers read. The tables holding your parsed code are reachable only by the service itself, never by a browser, whoever is holding it.

An API key, if you make one, is scoped to a single workspace and can be revoked without disturbing anyone else's.

3. How secrets are held

Nothing sensitive is stored in a form we could read back to you.

An API key exists in full exactly once, on the screen that creates it. What we keep is a one-way hash, so a copy of our database does not hand anyone a working key. If you lose one, we cannot recover it, which is the point.

If you connect your own database for schema mapping, the connection string is encrypted with a separate key held outside the database, using AES-256-GCM with a fresh nonce each time.

Passwords are hashed by Supabase Auth with bcrypt. We never see them, and neither does our own service, which verifies your session by asking the identity provider rather than by inspecting the token itself.

4. What runs on every change

The kind of mistake that causes a breach is caught by a machine, not a memory.

Every request that changes something is validated against a schema before it reaches the database, so a malformed or oversized field is refused with a reason rather than stored. Size and rate limits sit in the database itself, where they apply to every caller rather than to one code path.

Every week a job connects to the live database and fails if any table has lost its access rules, because that is the single mistake with the worst outcome and the easiest one to make. The rule it applies is tested on every push, alongside the rest of the tests, the types and the linting.

The site sends a content security policy, so the browser refuses to load a script or contact a server that is not on a list we maintain, and reports anything it blocks back to us.

5. The AI, specifically

It reads, it writes text back to you, and it can do nothing else.

The models have no tools, no database access and no ability to act. They receive a slice of your map and return words. Anthropic's API terms do not permit training on it.

Because cleap reads other people's code, the code itself is treated as untrusted input: it arrives inside a marked boundary with explicit instructions that it is material to describe and never instructions to follow. A repository that contains text shaped like a command, whether by accident or design, does not get to change what cleap tells you about your system.

What was sent and what came back is logged so you can see your own history and so we can investigate a bad answer. Disconnect a repository and that text is erased.

For workspaces that need code to stay within their own account: a workspace owner or admin can set their own Anthropic API key in the workspace settings. When configured, cleap's AI features use that key instead of cleap's, so your code reaches Anthropic directly from your account, and billing goes to you. The key is encrypted at rest and never shown or copied after it is saved.

6. Who we rely on

Seven companies, and what each of them can see.

We name them because you will need this list before you can sign anything, and because the alternative is a security questionnaire and a week of waiting.

CompanyWhat it doesWhere
GitHubWhere your code livesYour repository. cleap reads it with a read-only token you grant and can revoke.United States
SupabaseThe database, sign-in and file storageYour map, your workspace and who is in it, and your profile photo.AWS, us-east-1
RailwayRuns the service that reads repositoriesA working copy of a repository while it is being read, removed when you disconnect it.United States
VercelServes the web appRequests for the site itself. No repository content passes through it.United States
AnthropicThe AI featuresThe slice of the map a feature needs, and a code excerpt for a code-level question.United States
FirecrawlReads a link you paste as document contextThat one public page. Nothing from your repository.United States
ResendSends invitation and account emailThe recipient's email address and the message.United States

We will tell existing customers before adding a company to this list that can see repository-derived data.

7. Reporting a flaw

Email us, and you will hear back within three working days.

Write to hello@cleap.dev with “security” in the subject. Please do not open a public issue for anything exploitable. Machine-readable contact details are at /.well-known/security.txt, in the format researchers' tooling looks for.

What helps. Enough to reproduce it: the address or endpoint, what you sent, what came back, and what you think it lets someone do. A proof of concept is welcome. Video is rarely as useful as the request.

What we ask. Test against your own account and your own repositories. Please do not run automated scanners against the live service, degrade it for other people, or access, change or keep anyone else's data. If you reach someone else's data by accident, stop and tell us what you saw so we can measure it.

In scope. cleap.dev and app.cleap.dev, api.cleap.dev, the cleap-ingest GitHub App, and the public showcase maps.

Out of scope. Anything needing physical access, a stolen device or social engineering. Scanner output with no demonstrated impact. Missing headers or version disclosure with no exploitable consequence. Denial of service through sheer volume. And the companies in section 6, which have their own programmes.

We will not pursue anyone who reports in good faith under these terms. We will credit you by name if you would like that, and tell you what changed and when it shipped. There is no bounty yet, and the reason is in the next section.

8. What we don't have yet

The list every security page should have and most leave out.

No SOC 2 report. We are a small team and an audit covering a period we have barely existed for would certify very little. If a deal depends on it, tell us and we will start the clock.

No independent penetration test yet. Worth commissioning once, and worth it far more after the recent round of internal fixes than before.

No single sign-on. Two-step sign-in with an authenticator app is available on your account page. Requiring it of a whole workspace is not built yet, and that is the version an administrator actually wants.

One region. Everything runs in the United States. We cannot offer a residency commitment today.

No bug bounty. Answering reports quickly has to come before paying for them, and we would rather be good at the first thing before advertising the second.

Every claim here describes what the software does today, and this page changes when the software does. If something on it turns out to be wrong, that is a bug and we want to hear about it at the address in section 7.