Appendix B — Security Baseline
Last updated July 2026 · v.02
Required Appendix to the Master Services Agreement.
1. Purpose and Scope
This Security Baseline describes the administrative, technical, and physical safeguards Clasp maintains to protect Customer Data from unauthorized access, consistent with Section 5 (Data & Security) of the Agreement. This Appendix does not create or imply compliance with any specific regulatory framework or certification unless expressly stated.
2. Security Governance
Clasp maintains internal security policies governing:
access control
credential management
secrets management
incident response
change management
vendor and subprocessor review
acceptable use of internal systems
Clasp personnel with access to Customer Data are required to follow these policies and receive periodic security awareness training.
3. Access Control & Authentication
3.1 Role-Based Access Controls
The Service supports Firm User, Admin, and Super Admin roles. Access to administrative functions is restricted to authorized personnel.
3.2 Authentication Model
Clasp uses a one-time-password (OTP) authentication model for all login operations. OTP constitutes multi-factor authentication for purposes of this Agreement. OTP codes are delivered through an email-based authentication flow. Clasp does not support SSO, OAuth, SAML, Okta, or other identity-provider integrations.
3.3 Customer Responsibilities
Customer is responsible for securing email accounts used to receive OTP codes and for managing user provisioning and deprovisioning.
4. Data Storage & Encryption
4.1 Encryption at Rest
Customer Data stored within the Service is encrypted at rest using industry-standard encryption provided by Clasp’s cloud infrastructure.
4.2 Encryption in Transit
Customer Data transmitted between Customer and the Service is encrypted using HTTPS/TLS.
4.3 Customer-Managed Keys
Clasp does not currently provide customer-managed encryption keys. If introduced in the future, such features may limit or disable certain functionality, and Clasp will not be able to recover Customer Data if Customer mismanages its keys.
5. Secrets Management
Integration tokens, credentials, and system secrets are stored in an enterprise-grade secrets management system. Access to secrets is restricted to authorized personnel and logged within Clasp’s internal systems.
6. Data Processing Architecture
6.1 OCR & Text Extraction
Clasp uses Unstructured.io to perform OCR and extract text for indexing and search. OCR is read-only and does not modify document content.
6.2 Embeddings
Text embeddings generated for search and retrieval are stored in Clasp’s database. Embeddings may persist until configurable deletion logic is implemented.
6.3 No LLM Exposure
Customer Data is not transmitted to external large language models for training or inference. AI-Assisted Functionality operates on metadata or embeddings only.
7. Hosting & Infrastructure Security
7.1 Cloud Provider
Customer Data is stored in Google Cloud Storage in per-organization buckets. Clasp selects hosting regions and configurations; region selection is not configurable by Customer.
7.2 Backups & Durability
Clasp does not maintain separate customer-data backups outside of Google Cloud’s native durability and redundancy.
7.3 No DR/BCP Commitments
Clasp does not guarantee:
multi-region replication
disaster recovery RTO/RPO targets
secondary backup sites
cold-storage tiers
unless expressly stated in an Order Form.
8. Logging & Monitoring
8.1 Activity Logs
Clasp maintains lightweight activity logs showing significant actions within cases and tasks.
8.2 System Logs
Backend system logs may contain metadata necessary for debugging and operational monitoring.
8.3 No Audit Log Module
Clasp does not currently provide a customer-facing audit log or reporting module. Logs are not included in standard data exports.
8.4 Retention
Log retention periods may vary and are not guaranteed. Logs may persist in system backups until backup cycles expire.
9. Incident Response
9.1 Acknowledgment
Clasp will acknowledge receipt of Customer’s incident report within forty-eight (48) hours.
9.2 Investigation & Remediation
Clasp will use commercially reasonable efforts to investigate and remediate confirmed incidents.
9.3 Notification
Clasp will notify affected Customers without unreasonable delay following confirmation of an incident involving Customer Data.
10. Subprocessors
Clasp may use subprocessors to provide the Service, including cloud hosting, OCR, email delivery, messaging, payments, and AI-assisted features. The current list of subprocessors is provided in Appendix H and may be updated from time to time.
11. Customer Security Responsibilities
Customer is responsible for:
securing its own systems, devices, and networks
managing user access
safeguarding credentials
ensuring Customer Data submitted to the Service complies with applicable laws and professional obligations
promptly notifying Clasp of any actual or suspected unauthorized access
12. Limitations
This Security Baseline does not constitute:
SOC-2 compliance
ISO 27001 compliance
GDPR/CCPA compliance
HIPAA compliance
PCI-DSS compliance
any representation of meeting specific regulatory frameworks
Clasp reserves the right to update internal security practices consistent with industry norms, provided such updates do not materially reduce the protections described in this Appendix.