Workspace access
Client and application records are queried against the authenticated email. Access is available through Sign in with ChatGPT or a one-time code sent only to an email already attached to a Klarnow record. Team-only views have a separate authorised-email check.
No reusable password
Klarnow does not ask clients to create or reuse a password. Email codes expire in 10 minutes, work once and lock after five failed attempts. Requests are rate-limited without revealing whether an email exists.
Protected sessions
Portal sessions expire after 12 hours. Browser cookies are HttpOnly, Secure and SameSite=Lax; the corresponding server token is stored only as a cryptographic hash and can be revoked on sign-out.
Transport and browser controls
Traffic is served over HTTPS with strict transport, content-type, referrer, framing and browser-permission headers. Camera, microphone and location access are disabled for the public website.
Responsible disclosure
If you believe you have found a security issue, email team@klarnow.co.uk with enough detail for us to investigate. Do not access or alter another person’s data.