Security

Security at Cloove

How your account and your data are protected, what Cloove does when something goes wrong, and an honest account of what Cloove is and is not certified for.

Last updated: September 8, 2026

1. How we think about it

Cloove holds business records, customer conversations and financial information. This page describes how that is protected. It is deliberately specific, and it is deliberately limited to what is true today.

There are no certification badges on this page. Section 6 says plainly what Cloove does and does not hold, because a security page that implies more than it can evidence is worth less than one that does not.

2. Protecting your account

Authentication

Access to your account requires your credentials. Keep them, and your transaction PIN, to yourself - Cloove will never ask you for them.

PIN on money movement

Transfers and payouts require PIN confirmation. Nothing consequential happens on an assistant's initiative alone.

Role-based staff access

You decide what each member of your team can see and do. Permissions are per-role, not all-or-nothing.

Audit trails

Actions taken in your account are logged, so you can see what happened, when, and who did it.

3. Protecting your data

  • Data is encrypted in transit between your device and Cloove, and between Cloove and the services it integrates with.
  • Staff access to production systems is restricted to named individuals with a business need, and is logged.
  • Access follows the principle of least privilege and is reviewed periodically, and removed when someone leaves.
  • Production and development environments are separated, and production customer data is not copied into development or test environments.
  • Credentials and secrets are held in a secrets manager, not in code.

What Cloove collects and why is set out in the Privacy Notice, along with how long each category of data is kept.

4. Vendors and AI providers

Cloove depends on cloud infrastructure, messaging platforms, telephony providers and AI model providers. Each is assessed before engagement and contracted on terms that restrict what they may do with data Cloove sends them.

On AI providers specifically

Cloove contracts with its AI model providers on terms that do not permit customer content to be used to train their models, and configures its use of them accordingly. This is checked per provider rather than assumed.

5. When something goes wrong

No system is completely secure. Cloove has an internal procedure for identifying, containing and assessing security and personal data incidents, and for fixing whatever allowed one to happen.

Where a personal data breach is likely to result in a risk to people's rights and freedoms, Cloove will notify the Nigeria Data Protection Commission within the period required by law, and will inform affected individuals where the law requires it or where telling them would help them protect themselves. Where Cloove processes data on behalf of a business customer, Cloove will tell that business without undue delay so it can meet its own obligations.

6. Certifications, stated plainly

Cloove does not currently hold ISO 27001, SOC 2 or PCI DSS certification, and does not claim to. Where a Cloove product touches card data, that processing is carried out by the licensed payment provider handling the card transaction, under that provider's own certifications and obligations. A partner's certification covers the partner's systems, not Cloove's, and Cloove does not present it as its own.

Regulated financial services accessed through Cloove products are provided by licensed financial institutions, which operate their own security and regulatory controls. The division of responsibility is set out in the AML / CFT / CPF Policy.

As Cloove grows, so will this list. When something is added, it will be because the work has been done, not because a questionnaire asked for it.

7. Reporting a vulnerability

If you have found a security issue in a Cloove product, please tell us at security@clooveai.com. Include enough detail for us to reproduce it, and give us a reasonable opportunity to fix it before disclosing it publicly.

Cloove will not pursue legal action against researchers who act in good faith: who do not access or modify data beyond what is needed to demonstrate the issue, who do not degrade the service for anyone else, and who report to us promptly and privately.

If you think your own account has been compromised, contact support@clooveai.com immediately rather than waiting.

Found something?

Report a security issue to our team. We will acknowledge it, work with you on a fix, and we do not pursue researchers acting in good faith.

Report a vulnerability

security@clooveai.com