Security

Last updated: March 2026

Our Commitment

At Better CLM, security is foundational to everything we build. We employ industry-standard practices to ensure your documents and data remain protected at all times.

Encryption

In Transit

All data transmitted between your browser and our servers is encrypted using TLS 1.3. WebSocket connections used for real-time collaboration are also fully encrypted.

At Rest

Documents and user data are encrypted at rest using AES-256 encryption. Encryption keys are managed through a dedicated key management service.

Authentication

We use Google OAuth 2.0 for authentication. We never store passwords. Session tokens are short-lived and securely managed.

Infrastructure

  • Hosted on SOC 2 Type II certified cloud infrastructure
  • Automatic failover and redundancy across availability zones
  • Regular security audits and penetration testing
  • Automated vulnerability scanning of dependencies

Access Controls

Document access is governed by granular permissions. Only users explicitly invited to a document can view or edit it. All access events are logged for audit purposes.

Incident Response

We maintain a documented incident response plan. In the event of a security incident, affected users will be notified within 72 hours as required by applicable regulations.

Responsible Disclosure

If you discover a security vulnerability, please report it to support@betterclm.com. We appreciate responsible disclosure and will acknowledge your report within 48 hours.