Trust

Security

ClientCadence is built for client communication workflows where drafts, workspace history, and connected integrations should stay controlled, reviewable, and tied to the right account.

Last updated May 2026

On this page

Built for controlled client communication

Google OAuthWorkspace separationIntegration disconnectGitHub command controlsRate limitingStripe billingReview before sending

How we protect accounts and data

ClientCadence keeps workspace features tied to signed-in accounts. Projects, saved drafts, history, integrations, usage, and team activity are scoped to the workspace they belong to.

  • Signed-in users access workspace features through their account session.
  • Workspaces are separated so one team cannot browse another team's project records.
  • Team roles are used where workspace features require owner, admin, or member control.
  • Rate limits and abuse controls help reduce spam, automated misuse, and repeated expensive requests.
  • Billing is handled through Stripe, so ClientCadence does not store full payment card numbers.
  • Integrations use authorized app flows, including OAuth where supported, instead of asking for provider passwords.
  • Google sign-in uses limited account identity information needed to create and maintain your ClientCadence session.

Data protection and safeguards

ClientCadence uses reasonable administrative, technical, and operational safeguards intended to help protect accounts and workspace information. These safeguards are designed for a practical SaaS workflow, not as a guarantee that every risk can be removed.

No internet service, storage provider, integration, or transmission method can be guaranteed completely secure. Users should keep account access protected, disconnect integrations they no longer use, and avoid placing secrets or regulated data into drafting notes.

AI-generated communication review

ClientCadence drafts are meant to help you write faster, not replace your review. AI can make mistakes, miss context, or phrase something too strongly for a specific client situation.

Before sending or sharing a draft, check facts, dates, promises, pricing, deadlines, names, deliverables, and client-specific obligations. ClientCadence should not be treated as professional legal, financial, medical, tax, compliance, or security advice.

Cadence signals, blocker detection, quiet-client indicators, summaries, risk labels, and suggested next actions are automated estimates and may be inaccurate or incomplete.

Integration security

Gmail and Slack connections use authorized provider flows where applicable. OAuth lets users approve access without sharing their Google or Slack password with ClientCadence.

  • Gmail sending is designed for messages you approve from your connected account.
  • ClientCadence does not use Gmail access to read, scan, import, or analyze your inbox.
  • Slack actions are designed for approved commands, app messages, mentions, channel replies, and sending to selected channels.
  • Integrations should request only the permissions needed for the workflow.
  • You can disconnect Gmail or Slack from ClientCadence settings.
  • You can also revoke access directly from Google or Slack account and workspace settings.

Connecting an integration does not mean ClientCadence sends messages automatically. Gmail is used only for send actions you approve, and you remain responsible for reviewing and approving what leaves your workspace.

GitHub security and permissions

ClientCadence uses selected GitHub repositories to help users turn project activity into reviewed client-ready updates.

  • Users choose selected repositories during GitHub App installation or repository selection.
  • ClientCadence requests the permissions needed to import selected project activity and post issue/PR conversation replies for explicit commands.
  • Imported activity may include pull requests, issues, commit messages, tags, releases, labels, statuses, timestamps, and links.
  • Passive webhooks update ClientCadence signals quietly and do not post GitHub comments.
  • GitHub comments are posted only when a user writes an explicit /clientcadence or /cc command.
  • GitHub private key and client secret are stored as server environment variables and are not exposed to the browser.
  • GitHub webhook signatures are verified before payloads are processed.
  • GitHub installation access tokens are generated server-side and are not stored long-term.
  • GitHub tables are accessed through server routes, not directly by browser clients.
  • The current GitHub workflow does not store source code files, raw diffs, or patches.

ClientCadence does not create GitHub issues, edit or delete GitHub comments, create commits, create releases, merge pull requests, change repository settings, or make repository admin changes.

GitHub activity can help identify release signals, but users should review generated updates before sending or relying on them.

Workspace activity and audit visibility

Workspace activity records help owners and admins understand important account changes. Examples may include integrations being connected or disconnected, team and invite activity, billing plan changes, and other important account actions.

Activity review is designed for account oversight and troubleshooting. It is not a compliance archive, legal record system, or complete message-review system. Owners and admins may see shared workspace activity depending on role and feature usage.

History and retention controls

Workspaces can choose whether generated drafts save to History by default, and users can override that choice for individual drafts. Turning History off prevents generated drafts from being saved to workspace History, but it does not mean nothing is processed or retained.

Temporary processing, security logs, billing records, abuse-prevention logs, operational records, provider records, and backups may still exist where needed. Disabling History may reduce saved context, cadence signals, and future workflow memory.

Deleting a saved History item removes it from visible workspace History, but it does not undo emails, Slack messages, copied content, shares, provider records, or operational records that may already exist.

Sensitive data boundary

ClientCadence is intended for normal client communication notes, project updates, and drafts. Users control what notes they paste, and should avoid including secrets or regulated data unless they have determined it is appropriate for their work.

Do not paste:

  • Passwords, API keys, private keys, or account credentials.
  • Payment card numbers, bank details, or payment credentials.
  • Government IDs, health records, or protected personal data.
  • Regulated legal, tax, financial, security, or compliance records.
  • Confidential client information that should not be processed in a drafting tool.

Automated checks may block obvious high-risk content, but no filter catches every sensitive detail. Review rough notes before generation and review outputs before sending.

Context file safety

Context file uploads are limited by plan, file type, and size. ClientCadence extracts readable text from supported PDF, TXT, and Markdown files for the requested draft generation. It does not support OCR, arbitrary file analysis, or permanent file storage by default.

Uploaded files should not contain passwords, API keys, payment details, regulated records, or highly sensitive client data. ClientCadence validates uploads server-side and limits extraction to reduce abuse, privacy, and cost risk.

Operational safeguards

ClientCadence uses practical safeguards to keep the product reliable and reduce misuse. These include rate limiting, abuse prevention, reliability monitoring, input-size controls, and ongoing review of account, workspace, and integration permissions.

As the product grows, these controls will continue to improve. Security is treated as an ongoing operating practice, not a one-time checklist.

Service boundaries

ClientCadence is an AI-assisted workflow tool, not a regulated records platform, legal advisor, financial advisor, compliance system, or guaranteed delivery service. Users remain responsible for reviewing drafts, confirming recipients, preserving records they need, and deciding whether a message should be sent.

Gmail, Slack, GitHub, Stripe, Google login, email delivery, hosting, AI providers, analytics, and other providers may have their own outages, limits, policies, security practices, and account controls.

Features that rely on third-party providers, including AI generation, Gmail, Slack, GitHub, hosting, authentication, billing, email delivery, or analytics services, may become temporarily unavailable, rate limited, delayed, modified, or discontinued outside ClientCadence's control.

ClientCadence does not guarantee delivery, receipt, inbox placement, message visibility, or successful transmission through third-party providers such as Gmail or Slack.

SOC 2 status

ClientCadence has not completed a SOC 2 audit. We do not claim SOC 2 certification or enterprise security certification at this time.

Enterprise vendor reviews, SOC 2 readiness work, formal control evidence, and external audits would be handled as a later readiness process.

Contact

For security questions, vulnerability reports, abuse reports, or account concerns, contact support@clientcadence.io.

Related guides

Start with a controlled workspace

Draft from a project workspace first, then connect Gmail or Slack when you are ready to send reviewed messages.

Get started