Security center

Security you can understand before you pay.

These are the active protections around account access, company data, support requests, and subscription billing. No online service can promise zero risk, so we also make reporting straightforward.

Protected account access

Workspace routes require verified ChatGPT sign-in. Access decisions are enforced on the server, not only hidden in the interface.

Separated company records

Jobs, clients, team members, actions, and support history are stored with a workspace identifier and checked on every update.

Payment data stays with Paddle

Checkout is opened through Paddle as Merchant of Record. ClenoraOps does not receive or store full card numbers or security codes.

Verified billing events

Subscription changes are accepted only after signature verification, timestamp validation, and replay-resistant event recording.

Service health monitoring

A minimal health endpoint checks application and database availability without exposing customer records, configuration, or credentials.

Portable workspace backup

The authenticated owner can export operational records and audit history. Payment credentials and application secrets are excluded.

Report a security concern

Use the protected support form and select Security. Do not include passwords, verification codes, or payment-card information.

Contact security