Klientele is built for service businesses that handle confidential client data — legal matters, patient information, retainer financials. Here's exactly how we protect it.
TLS 1.2+ in transit. AES-256 at rest. Passwords bcrypt-hashed with 12 rounds. Never logged.
Every query filtered by workspace ID. No client-side filtering, no shared queues, no cross-tenant leaks.
RBAC out of the box. MFA on every account. SAML SSO on Agency tier and bespoke contracts.
Every change logged with IP, user-agent, and integrity-hashed chain on Agency tier. Up to 7 years retention.
Hosted on Kubernetes in India. VPC-isolated. Backed up daily, retained 30 days. Point-in-time recovery.
Built with SOC 2 controls; formal certification in 2027. HIPAA-conscious + BAA available. Legal: 7-year retention.
Encrypted in transit between every client and our edge. HSTS enforced.
Encrypted at rest. Per-tenant keys. Cryptographic key rotation.
Role-based access plus workspace isolation. Every query filtered by workspace_id.
Every write appended to a tamper-evident, hash-chained activity log.
Point-in-time recovery. Rolling daily snapshots retained per plan tier.
Every byte that enters Klientele moves through these four stages. Encrypted in transit, encrypted at rest, written to a tamper-evident log.
For prospects with security questionnaires, this is the long version. Bring your questionnaire to a sales call and we'll fill it in line by line.
workspace_id; no client-side filtering, no shared queues, no cross-tenant leaks.Klientele is built with the technical controls a SOC 2 audit would require — integrity-hashed audit logs, encryption-at-rest, role-based access, change management, vendor due-diligence. Formal SOC 2 Type II certification is on the roadmap for 2027.
For healthcare customers, Klientele includes HIPAA-conscious controls (extended audit retention, PHI-access logging, role-based PHI visibility). A Business Associate Agreement is available on Agency-tier contracts.
Legal practices: 7-year audit retention by default on the Legal template, tamper-evident chain, role-isolated matter visibility.
Klientele uses a small, vetted list of subprocessors. Each was selected for security posture and contracted under data-protection terms.
Material additions to this list are announced in advance to all workspace admins.
We don't yet run a formal public bug bounty programme. We do reward responsibly-disclosed vulnerabilities on a case-by-case basis (recognition, credits, or cash for critical findings). Email [email protected] with details before disclosing publicly.
Last updated May 16, 2026. © 2026 Codefree Systems & Technologies Pvt. Ltd.
Compliance teams, security architects, IT leads — talk to our team. We'll fill your questionnaire line by line and share the latest pentest under NDA.