Docs

Privacy & security

This page states plainly what Clawgnition holds, what it deliberately never holds, how access to your data is kept narrow and short-lived, and the limits we do not paper over. It ends with how to report a security problem.

Privacy by construction

Clawgnition's privacy does not rest on a promise to behave. It rests on the fact that your data is encrypted on your device before it ever reaches us, with a key that never leaves your machine. We only ever hold sealed bytes we cannot read. Put simply: we cannot read your data, because we were never given the means to.

What we hold, and what we never hold

What Clawgnition holds What Clawgnition never holds
Sealed snapshot bytes — encrypted by your device, opaque to us Your encryption keys
Accounting metadata: byte and object counts, snapshot order, retention state The readable contents of your vault — file paths, sizes, or text
Account basics: your email, sign-in details, billing state Long-lived storage credentials

The internal shape of your vault — which files exist, how big they are, how they are organised — is inside the sealed data and is opaque to us. We keep only the counts and version bookkeeping needed to store, list, and bill your snapshots.

Access is scoped and short-lived

When centraid needs to move bytes, Clawgnition issues permission that is deliberately narrow:

  • Scoped to one vault. A permission grant applies to a single vault's storage area and a single mode — read, or read-and-write — nothing wider.
  • Short-lived. Grants expire quickly on their own. centraid requests a fresh grant per sync run rather than holding a standing storage credential.
  • Reads stay available even when writes are paused. If your account is past due or a vault is winding down, you can still read and export — see Leaving.

What an operator can and cannot see

A Clawgnition operator can see that a vault exists, how many snapshots it has, and how much storage it uses — the bookkeeping needed to run the service. An operator cannot open your vault or read anything inside it, because the sealed bytes require a key we never hold. See How it works for the full picture.

The same design that keeps us out also means we cannot recover your data if you lose your encryption key. Real end-to-end encryption cuts both ways. Keep a safe copy of your key — Your keys explains how.

Limits we state plainly

We would rather tell you the boundaries than let you assume something untrue:

  • No third-party security certification yet. Clawgnition does not hold a SOC 2 or similar audit today.
  • No paid bug bounty. We handle reports carefully and on a best-effort basis, but we do not currently offer monetary rewards.
  • Revoking an API key has a short tail. Deleting a key stops new storage permissions immediately, but a permission that was already issued from it keeps working until it expires on its own — up to about 24 hours for a read grant, or an hour for a write grant. If you suspect a key was stolen, revoke it and treat that window as the time to stay alert.

Reporting a vulnerability

If you find a security problem in Clawgnition, please report it privately rather than filing a public issue.

  • Email legal@clawgnition.ai.
  • Use a subject line like [clawgnition security] <short description>.
  • Include how to reproduce it and the impact you expect. Please redact your own API key and any other person's data.

We aim to acknowledge reports promptly and to work with you on a reasonable disclosure timeline — at minimum until a fix has shipped or a documented workaround exists.

Common questions

Is my data encrypted, and who did the encrypting?

Yes. centraid encrypts it on your device before upload, using a key that stays on your device. We store the encrypted result and never see the key. See How it works.

Could a court or a hacker force you to hand over my readable data?

We can only ever produce the sealed bytes we hold, which are unreadable without your key. We do not have the key and cannot unseal your vault for anyone.

What should I do if I think my API key leaked?

Delete that key and create a new one for centraid. Because a stolen key may already have requested a short-lived read grant, treat the following day as a window to watch. See Your keys.