Trust & Security Center
Last Updated: August 19, 2026
CLAJAMA is built for business owners who treat their customers' data as seriously as their own. This page states our security posture, the compliance programs we run, and exactly how we handle the data you trust us with.
SOC 2
SOC 2-aligned. Controls are mapped to the AICPA Trust Services Criteria and operating today. Audit in progress.
ISO 27001
ISO/IEC 27001-aligned. Our ISMS controls are mapped to Annex A, with formal certification in progress.
HIPAA-ready
We sign Business Associate Agreements (BAAs) for covered entities. No PHI is stored without a BAA in place.
GDPR / CCPA
Full data-subject rights — access, correction, export, and erasure. Data Processing Agreement available.
How we protect your data
- Encryption in transit. All traffic is TLS 1.2+ with HSTS. Your browser talks to us over an encrypted connection, always.
- Access control. Every account supports two-factor authentication (TOTP, email OTP, and recovery codes). Session tokens are validated on every request.
- Least privilege. Role-based access separates users from admins, and workspaces are isolated per tenant — your site data is never visible to another customer.
- Audit logging. Activity, session journeys, and system events are logged so we can detect and investigate anomalies.
- Backups & monitoring. Database backups run nightly, uptime and disk are monitored 24/7, and every deploy is verified with checksums.
- Incident response. We have a documented response plan with severity tiers, notification commitments, and post-incident review. See our security page.
Our compliance posture — stated truthfully
- SOC 2: CLAJAMA operates controls mapped to the AICPA Trust Services Criteria (security, availability, confidentiality, processing integrity). We have not yet completed a third-party audit, so we do not claim "certified" — we are SOC 2-aligned and working toward a Type II report.
- ISO/IEC 27001: Our information security management system is mapped to Annex A controls and in operation. Certification is in progress; until the accredited audit completes we are ISO 27001-aligned.
- HIPAA: CLAJAMA is a potential Business Associate. We are HIPAA-ready: we sign BAAs, enforce the Security Rule safeguards we can operate today, and do not store PHI unless a service requires it under an executed BAA. Contact us to execute a BAA.
- GDPR / CCPA: We process data under a Data Processing Agreement, honor access/erasure/portability requests, and do not sell personal data.
Data handling commitments
- We never sell your data. Period.
- We do not use your data to train models. Your chat, content, and business data are never used to train third-party AI models. AI providers are bound by data processing agreements.
- Purpose-limited processing. We collect only what your service needs — the intake interview asks for required fields and nothing else.
- You own everything you build. Your sites, content, and data belong to you. Export or delete them whenever you want.
- Minimal subprocessors. A short, disclosed list — hosting, payments, AI models, images. See the full list on our DPA page.
Payments
Card payments are processed by Square (PCI DSS Level 1). Card numbers never touch our servers — we only receive payment status and order references. Payment webhooks are cryptographically verified and rejected when they cannot be authenticated.
Legal & compliance documents
- Privacy Policy — what we collect, why, and your rights.
- Terms of Service — the rules of the road.
- Data Processing Agreement & Subprocessors — GDPR/CCPA terms and our vendor list.
- Security & Vulnerability Disclosure — how to report a security issue.
- security.txt — machine-readable security contact.
Questions?
Contact us any time at help@clajama.com — security questions go to security@clajama.com.