01.Our approach
clive watches your stream and keeps what it cuts. That is a lot of trust to ask for, so this page sets out the controls we actually run today. It is deliberately specific about what we have not built yet, because a security page that only lists strengths is not much use to anyone.
02.Encryption
- In transit. Traffic between your browser, our API, the watcher, and our storage runs over TLS.
- At rest. Captured segments, finished clips, and database content are encrypted at rest.
- Payment data. Full card numbers never reach us. They go directly to our payment processor and we hold only a tokenised reference.
03.Stream data
- Captured media is stored in private buckets and served through a restricted-origin CDN distribution, never from public URLs.
- Platform tokens from a linked Twitch or Kick account are stored scoped to the access clive needs, and you can unlink at any time from your settings.
- Retention of captured material is covered in our Privacy Policy. Deleting a clip propagates to our object storage.
04.Access control
- Multi-factor authentication is mandatory for every engineer with production access.
- Each provider we use is issued scoped credentials limited to its function. No provider holds a general-purpose key.
- Access logs are reviewed routinely, not only after an incident.
05.Infrastructure
clive runs on Amazon Web Services in the United States. The full list of providers that touch your data is on our sub-processors page.
06.Telemetry and logging
Error and performance telemetry is scrubbed and aggregated before it leaves our systems, so crash reports do not carry your stream content or message contents.
07.Where we are not yet
Plainly, so nothing here is implied that is not true:
- We do not hold SOC 2, ISO 27001, or any equivalent third-party certification.
- We have not completed an independent penetration test.
- We do not run a paid bug bounty, though we do respond to reports.
We would rather say so than let a badge imply otherwise. If your organisation needs any of the above before using clive, talk to us about timelines rather than assuming.
08.Reporting a vulnerability
Found something? Email security@skeet.now with enough detail to reproduce it, and give us a reasonable window to respond before disclosing publicly.
We will not pursue legal action against researchers acting in good faith who avoid privacy violations and service degradation, and who do not access or modify data belonging to other users.