Effective date: August 27, 2026
At MenuClaw, security is a core part of how we build and operate the Service. This page describes the controls and practices we apply to protect the data we process — from encryption and access control to application security and incident response.
01Our Approach
Defense in depth, aligned with SOC 2
We follow a defense-in-depth strategy aligned with SOC 2 principles: controls are layered across people, process and technology, and every control is reviewed on a regular cadence. Security requirements are considered at design time for every product change.
02Encryption
Encrypted in transit and at rest
- All traffic to and from the Service is encrypted with TLS 1.2 or higher.
- Data at rest is encrypted with AES-256.
- Encryption keys are managed through a dedicated key-management system, rotated on schedule, and access to keys is logged and restricted.
03Access Control
Least privilege, verified identities
- Access to production systems is granted on a least-privilege, role-based basis and requires multi-factor authentication.
- Staff access is reviewed regularly and removed when no longer needed.
- All sensitive operations are logged and auditable.
04Application Security
Secure by design
- We build with a secure development lifecycle: code review, automated dependency and vulnerability scanning, and security testing before release.
- We run regular penetration tests and apply OWASP guidance to the application layer.
05Infrastructure & Operations
Hardened, monitored, resilient
- The Service runs on hardened, monitored cloud infrastructure with automatic backups, disaster-recovery procedures and a 99.99% uptime target.
- We operate 24/7 monitoring and a documented incident-response plan with defined roles, escalation paths and post-incident reviews.
06Data Privacy & Compliance
Privacy and compliance commitments
- We process data in line with our Privacy Policy and applicable data-protection law, including GDPR and CCPA where relevant.
- We sign data processing agreements with customers and vetted subprocessors, and we can provide our SOC 2 report under NDA on request.
07Responsible Disclosure
Reporting security vulnerabilities
If you believe you have found a security vulnerability in the Service, we encourage you to report it privately to security@menuclaw.com. Please include a description of the issue, steps to reproduce and any proof-of-concept. Do not test in ways that disrupt the Service or access other users' data. We will acknowledge reports promptly and work toward a fix within 90 days.
08Contact
Get in touch with our security team
For security questions, reports or compliance requests: security@menuclaw.com.