Security at ClawSplit

Data Handling

ClawSplit stores A/B test configurations, prompt variants, and statistical results. Test payloads may include sample inputs used for evaluation. All experiment data is scoped to your workspace and deleted when experiments are archived. We never use your prompt data to train models or share it across accounts.

Encryption

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). API keys and credentials are stored using industry-standard secret management.

Infrastructure

Hosted on European infrastructure. Application containers are isolated per deployment. No shared tenancy between customers.

Access Control

Experiments are scoped per workspace with role-based access. Prompt variants and test results cannot be accessed across workspaces. API keys for experiment triggers are individually scoped and revocable.

Compliance Roadmap

  • SOC 2 Type I — targeting Q3 2026
  • GDPR — compliant by design (EU hosting, data minimization, right to deletion)

Responsible Disclosure

Found a vulnerability? Email security@clawsplit.com. We respond within 48 hours.

Questions

For security inquiries, contact security@clawsplit.com.