clika
Log inGet started
Trust & safety

Security at Clika

Clika is the control room for a family of business apps. Identity, billing, and entitlements live in one hardened control plane so security is consistent across every app you run.

Last updated · May 2026
One identity, centrally controlled
Clika owns authentication, sessions, and entitlements. Every app trusts a single sign-in, so access can be granted or revoked from one place.
Encryption in transit and at rest
All traffic runs over TLS, and data is encrypted at rest. Secrets and tokens are never exposed to product apps beyond what each one needs.
Tenant isolation
Each organization's data is scoped to its tenant. Apps own their own world — patients, students, customers — while Clika enforces who can reach them.
Least-privilege entitlements
Subscriptions map to apps. A team only sees the apps its plan unlocks, and operator overrides are logged and reversible.

Authentication & access

Sign-in is handled once by Clika. Access tokens are short-lived and refreshed transparently; refresh tokens are stored in httpOnly cookies that JavaScript cannot read. Team membership and roles determine what each person can open.

Data handling

We collect the minimum needed to run your account — names, work email addresses, organization details, and billing metadata. Clika never asks you to store bank numbers, card numbers, or government IDs with us; payments are processed by our payment partners.

Reporting a vulnerability

Found something? Email security@clika.dev with steps to reproduce. We acknowledge reports within two business days and will keep you updated as we investigate. Please give us a reasonable window to remediate before any public disclosure.