Security & privacy

Security and privacy you can review.

Castle Entropy is built with data isolation, least-privilege access, encryption, and audit trails. Report a concern any time to security@cleargarment.com.

Security approach

Data isolation

Each customer's data is isolated by design, so one customer's information is never exposed to another.

Least-privilege access

Role-based access controls; users and integrations get only the permissions they need.

Audit trails

Sensitive actions are recorded to a reviewable audit trail for internal review and assurance.

Encryption

Encryption in transit and at rest, using approved infrastructure controls.

Human approval

High-impact actions require authorized human approval — nothing sensitive happens automatically.

Content safety checks

Content is checked for known threats before it is retained, so malicious material isn't carried into your records.

Abuse resistance

The API is protected with authentication, rate limiting, and strict input validation.

Credential controls

API credential controls support rotation and revocation.

Privacy stance

  • Customer data is processed only for the documented service purpose.
  • Customer personal data is not used for model training, advertising, or another customer's benefit without explicit written authorization.
  • Deletion and return workflows are supported.
  • Sub-processors are tracked; new sub-processors handling customer personal data are not activated without required notice and approval.

Customers remain responsible for providing notices, honoring applicable rights requests, and deciding lawful retention rules. Castle Entropy supports the technical workflow; it does not replace your privacy or legal obligations.

Responsible disclosure

If you believe you have found a security issue, please contact us before disclosing publicly. We investigate every report.

security@cleargarment.com

For security teams

Evaluating Castle Entropy? We share our detailed security and privacy documentation, architecture overview, and data-processing terms with prospective customers under a mutual agreement.

Request our security pack