ClashWise

Security and data protection

Understand the controls around your data.

Account protection, access permissions, AI processing and hosting: the practical details for evaluating ClashWise.

Authentication

Passwords are hashed with BCrypt (work factor 10); we never store or log a plain-text password.

Optional two-factor authentication (TOTP, RFC 6238) can be enabled per account. The shared secret is encrypted at rest with AES-GCM (authenticated encryption, so a tampered secret fails closed instead of silently decrypting to something else), and is backed by single-use recovery codes.

Account and session details
  • Repeated failed sign-in attempts trigger a lockout: 5 failed attempts locks the account for 15 minutes.
  • Refresh tokens rotate on use, are stored only as a SHA-256 hash (never the raw token), and are revoked immediately on logout.

Access control

Authentication is required by default. Public endpoints are explicitly marked; access to customer data is governed by the relevant permissions.

Sensitive endpoints (sign-in, password reset, personal-data export, and similar) are rate-limited per IP address to blunt brute-force and scraping attempts.

Security-relevant actions; logins, admin impersonation, permission changes, billing changes, and tool calls from AI features and connected applications; are written to an audit trail retained for 7 years.

Connected-app controls

ClashWise exposes a Model Context Protocol (MCP) server so customers can connect MCP-compatible AI clients and IDEs. Access is off by default; an organization admin must enable it, and each member can only use the capabilities an admin has granted them; viewing clash data and editing clashes are separate permissions.

  • Connections authenticate with the OAuth 2.1 authorization-code flow with PKCE (S256 enforced). Access tokens are bound to the ClashWise API audience; connection refresh tokens rotate on use and, like our session tokens, are stored only as a SHA-256 hash.
  • High-impact clash edits are never applied directly: the connected client receives the exact before-and-after preview and must explicitly confirm it before ClashWise applies the change.
  • Every tool call is recorded; visible to the user and to organization admins in the product, and retained in the audit trail above.
  • A connection can be revoked at any time from Connected apps; revocation blocks the connection’s next token refresh.

Connected AI clients are selected by you. Data they retrieve is handled under the client provider’s own terms.

Read the MCP setup guide

Data protection

HTTPS protects data in transit. Security headers include HSTS and content-type protections.

Encryption of our database and file storage at rest is provided by our cloud infrastructure (Microsoft Azure); we do not layer an additional custom database-encryption control on top of the provider default.

Transport and storage details
  • Two-factor secrets are encrypted with AES-GCM.
  • Password-reset and account-activation tokens are encrypted before storage.
  • Refresh tokens are never stored in plain text; only a SHA-256 hash.

Production database backups support a 30-day point-in-time restore window. A restore exercise was completed on 13 July 2026; its results describe that exercise, rather than a recovery-time commitment.

Privacy rights

Request account deletion in the app. The account is deactivated, with a 30-day recovery period before the purge process. Audit records follow their separate retention policy.

Personal-data export is available from your account. You can also delete individual Wise conversations in the product.

Published retention periods

Diagnostic errors
90 days
User activity
180 days
Wise conversations
12 months
Admin audit trail
7 years
Privacy policy

AI processing

Local naming and cloud AI have different data boundaries. Review the settings and the workflow you choose.

Cloud features; including the Wise assistant, summaries, and cloud-based analysis; use Microsoft Azure OpenAI. The Azure OpenAI resource and stored data are provisioned in Sweden, but the current GlobalStandard deployment may process prompts and responses in other Azure geographies.

The Navisworks plug-in can generate clash titles locally using a downloaded model. Successful local title generation runs on the customer workstation and uses clash metadata, not model geometry.

AI processing details

Cloud fallback is optional and disabled by default for the separate title workflow. If enabled, or if its local provider cannot be created, a naming request may be sent for cloud processing. The optional local-title stage in Run & Publish has no cloud fallback; failed titles keep their current text.

Local title modifications may synchronise limited audit metadata, such as the user ID, clash identifier, generated title, naming settings, timestamp, Navisworks filename, and source-model filenames.

Customer data is not used by ClashWise to train or fine-tune its AI models. Local models run on the customer workstation; Azure OpenAI processing is subject to Microsoft’s applicable data-use terms.

Read the local AI guide

Data residency & hosting

Database, file storage and transactional email
United Kingdom
Application hosting
Germany
Azure OpenAI resource and stored data
Sweden

GlobalStandard AI processing can take place in other Azure geographies. This is not an EU/EEA-only data-residency offering.

Review subprocessors

Report a vulnerability

Contact support@clashwise.ai with the affected page or workflow and steps to reproduce the issue. Please leave passwords, access tokens and customer project data out of the initial message.

Contact security support

Procurement and security reviews

For a questionnaire, current assessment status or specific hosting requirements, contact our team. This page is a product summary; contractual terms belong in the applicable agreements.