Security and Data Handling Statement

Effective date: 2026-02-05

Our approach

We aim to minimize the sensitive data you share and to use least-privilege access patterns.

What you should not send

  • Passwords
  • Private keys
  • Long-lived AWS access keys
  • Full disk images or anything that contains secrets

If you accidentally send sensitive information, notify us immediately at Support@openclaweasystart.com.

What you may share

  • AWS Account ID (12-digit)
  • Region and instance type
  • Non-secret log output (we still recommend reviewing before sending)
  • Error messages from installation steps

Access guidance

If access is required for White Glove:

  • Use an AWS IAM role with least privilege
  • Prefer time-bounded access and rotation
  • You control what permissions are granted and can revoke access at any time

Storage

We store support communications and work artifacts only as needed to deliver the Service and for reasonable support follow-up.