Authentication and access control
Clerk provides authentication and organization context. The application verifies sessions and limits access by organization and role.

Security practices
This page describes implementation details verified in the current product architecture. It does not claim certifications, guarantees, or independent assessments that have not been completed.
Clerk provides authentication and organization context. The application verifies sessions and limits access by organization and role.
Account sources, assignments, and access checks are organization-scoped. Dashboard assignments belong to a connected HighLevel location.
PIT and OAuth credentials are encrypted by the application before D1 storage and are not returned to browser clients.
Public embeds read cached D1 dashboard snapshots. They never call HighLevel directly from the iframe.
Aggregate reporting is retained for the dashboard. Recent capped drilldown data and pagination state are encrypted; older history is bounded to aggregate data.
Authorized source managers can disconnect an account, invalidating the embed and clearing the associated source data.
Security reporting contact details are not published until an active, monitored intake is approved. Do not submit credentials, tokens, embed keys, passwords, or customer exports through website forms. See the launch checklist for the security-contact requirement.
Data usageSubprocessorsReady when your next client is
Start with one connected account, explore the templates, or tell us how you deliver client reporting today.