Last updated 7 October 2026
Your data stays yours
Workspace content is only used to run your workspace. It's never sold, and never used to train anyone's AI models.
Isolated by design
- Cloverr runs on Oracle Cloud Infrastructure, in an isolated container on an isolated private network.
- Only the web entry point is reachable from the internet. The database and internal services are not.
AI teammates only see what you allow
- Each Bee has its own access settings (read mail, read docs, create tasks, and so on), and it can't read anything outside them.
- Reading web pages is a separate permission that organisation owners control.
- Every Bee action is logged on its Trail.
Every outgoing email is checked
- An AI reviewer checks emails leaving your organisation.
- Anything that looks like phishing, leaked secrets or abuse is held for a person to review, not sent.
Account security
- Email verification, and optional login verification codes on new devices.
- Alerts for sign-ins from new devices.
- Breached-password checks and rate limits on sign-in.
Encryption
- All traffic uses HTTPS (TLS).
- Passwords and sign-in codes are stored only as hashes.
- Credentials for connected services are encrypted at rest.
Private by default
- Personal mail and personal calendars are visible only to their owner.
- What each role can do is set by your organisation's owners.
Respecting the people you email
- Emails sent from Cloverr to outside addresses include a way to stop further emails.
- Once someone uses it, Cloverr won't let your workspace email them again.
Links
- Links in chat are checked before they're posted.
- Opening a link to another site always shows where it really goes.
Reporting a security issue
Found a vulnerability? Email kyle@imkylejk.me with the details. Please give us a reasonable time to fix it before sharing it publicly. We're grateful for responsible reports.