Appendix B — Security Baseline

Last updated July 2026 · v.02

Required Appendix to the Master Services Agreement.

1. Purpose and Scope

This Security Baseline describes the administrative, technical, and physical safeguards Clasp maintains to protect Customer Data from unauthorized access, consistent with Section 5 (Data & Security) of the Agreement. This Appendix does not create or imply compliance with any specific regulatory framework or certification unless expressly stated.

2. Security Governance

Clasp maintains internal security policies governing:

  • access control

  • credential management

  • secrets management

  • incident response

  • change management

  • vendor and subprocessor review

  • acceptable use of internal systems

Clasp personnel with access to Customer Data are required to follow these policies and receive periodic security awareness training.

3. Access Control & Authentication

3.1 Role-Based Access Controls

The Service supports Firm User, Admin, and Super Admin roles. Access to administrative functions is restricted to authorized personnel.

3.2 Authentication Model

Clasp uses a one-time-password (OTP) authentication model for all login operations. OTP constitutes multi-factor authentication for purposes of this Agreement. OTP codes are delivered through an email-based authentication flow. Clasp does not support SSO, OAuth, SAML, Okta, or other identity-provider integrations.

3.3 Customer Responsibilities

Customer is responsible for securing email accounts used to receive OTP codes and for managing user provisioning and deprovisioning.

4. Data Storage & Encryption

4.1 Encryption at Rest

Customer Data stored within the Service is encrypted at rest using industry-standard encryption provided by Clasp’s cloud infrastructure.

4.2 Encryption in Transit

Customer Data transmitted between Customer and the Service is encrypted using HTTPS/TLS.

4.3 Customer-Managed Keys

Clasp does not currently provide customer-managed encryption keys. If introduced in the future, such features may limit or disable certain functionality, and Clasp will not be able to recover Customer Data if Customer mismanages its keys.

5. Secrets Management

Integration tokens, credentials, and system secrets are stored in an enterprise-grade secrets management system. Access to secrets is restricted to authorized personnel and logged within Clasp’s internal systems.

6. Data Processing Architecture

6.1 OCR & Text Extraction

Clasp uses Unstructured.io to perform OCR and extract text for indexing and search. OCR is read-only and does not modify document content.

6.2 Embeddings

Text embeddings generated for search and retrieval are stored in Clasp’s database. Embeddings may persist until configurable deletion logic is implemented.

6.3 No LLM Exposure

Customer Data is not transmitted to external large language models for training or inference. AI-Assisted Functionality operates on metadata or embeddings only.

7. Hosting & Infrastructure Security

7.1 Cloud Provider

Customer Data is stored in Google Cloud Storage in per-organization buckets. Clasp selects hosting regions and configurations; region selection is not configurable by Customer.

7.2 Backups & Durability

Clasp does not maintain separate customer-data backups outside of Google Cloud’s native durability and redundancy.

7.3 No DR/BCP Commitments

Clasp does not guarantee:

  • multi-region replication

  • disaster recovery RTO/RPO targets

  • secondary backup sites

  • cold-storage tiers

unless expressly stated in an Order Form.

8. Logging & Monitoring

8.1 Activity Logs

Clasp maintains lightweight activity logs showing significant actions within cases and tasks.

8.2 System Logs

Backend system logs may contain metadata necessary for debugging and operational monitoring.

8.3 No Audit Log Module

Clasp does not currently provide a customer-facing audit log or reporting module. Logs are not included in standard data exports.

8.4 Retention

Log retention periods may vary and are not guaranteed. Logs may persist in system backups until backup cycles expire.

9. Incident Response

9.1 Acknowledgment

Clasp will acknowledge receipt of Customer’s incident report within forty-eight (48) hours.

9.2 Investigation & Remediation

Clasp will use commercially reasonable efforts to investigate and remediate confirmed incidents.

9.3 Notification

Clasp will notify affected Customers without unreasonable delay following confirmation of an incident involving Customer Data.

10. Subprocessors

Clasp may use subprocessors to provide the Service, including cloud hosting, OCR, email delivery, messaging, payments, and AI-assisted features. The current list of subprocessors is provided in Appendix H and may be updated from time to time.

11. Customer Security Responsibilities

Customer is responsible for:

  • securing its own systems, devices, and networks

  • managing user access

  • safeguarding credentials

  • ensuring Customer Data submitted to the Service complies with applicable laws and professional obligations

  • promptly notifying Clasp of any actual or suspected unauthorized access

12. Limitations

This Security Baseline does not constitute:

  • SOC-2 compliance

  • ISO 27001 compliance

  • GDPR/CCPA compliance

  • HIPAA compliance

  • PCI-DSS compliance

  • any representation of meeting specific regulatory frameworks

Clasp reserves the right to update internal security practices consistent with industry norms, provided such updates do not materially reduce the protections described in this Appendix.