← Back to ClearCue App Enterprise Infrastructure

Security & Compliance Standards

ClearCue is engineered with defense-in-depth principles designed to satisfy the strict data governance requirements of insurance agencies, commercial brokerage networks, and BPO operations.

🔐 Encryption in Transit

Enforced HTTPS with TLS 1.3 across GitHub Pages CDN, Render Web Services, and MongoDB Atlas database clusters.

🛡️ Multi-Tier RBAC

Cryptographic JWT tokens and strict server middleware enforce isolation between Master, Admin, Teacher, and Trainee roles.

⚡ In-Memory Heuristics

Zero third-party telemetry for everyday coaching checks. NLP analyses are processed ephemerally in RAM.

1. Cloud Infrastructure & Hosting Security

ClearCue employs a decoupled zero-trust microservice architecture:

2. Authentication & Credential Storage

User passwords are never stored in plaintext. ClearCue hashes all credentials using industry-standard bcrypt with high-work-factor salt rounds. API communication is authenticated using stateless, tamper-evident JSON Web Tokens (JWT) signed with 256-bit cryptographic secrets.

3. Disaster Recovery & High Concurrency

The platform features automatic dual-engine persistence with seamless failover, ensuring that operations remain functional with zero service disruption even during external cloud maintenance windows.

4. Vulnerability Disclosure

We welcome responsible security disclosures. If you discover a vulnerability, please reach out directly to our security engineering team at security@clear-cue.onerishi.in.