The analysis layer for identity.
See the whole access picture. Keep it on your machine.
Every IGA, IDP, directory, and app already exports its data. Cleave ingests it all, resolves who can actually reach what, and shows the picture no single vendor structurally can.
- Local-first. Nothing leaves this machine
- Deterministic. Every finding carries its why
- Read-only. Never touches provisioning
One group was granted.
Forty-seven things were reached.
Every IGA, directory, and app can tell you what it granted. None of them can tell you what that grant actually reaches once nested groups resolve. Cleave reads the exports you already have, resolves effective access across all of them, and shows you the picture no single vendor structurally can.
Findings that carry their reasoning
Every finding states why it fired, against which peer group, and with which parameters. An auditor can check the working — and the same data with the same parameters always produces the same result, so two people running the same review agree.
Access outlierCritical
Holds VPN_ADMIN_GROUP where none of their 34 department peers do. Rarity is weighted by how specific the entitlement is, so an admin group outranks a building pass.
Duty conflictCritical
Can both raise and approve payment. Evaluated against effective access, so a conflict assembled out of two nested groups is still caught.
Role candidateProposal
41 identities share the same 12-entitlement bundle. Exportable as a role model your IGA can actually consume.
HygieneSerious
Orphan accounts, dormant accounts, entitlements nobody holds, and accounts still live after a termination date. When a source ships no last-login data, the report says the check did not run — never that it passed.
Three steps, on your machine
Import what you already export
Drop in CSV or Excel exports. Cleave detects the delimiter and encoding, finds the header when it is not on row one, handles packed multi-value cells, and quarantines rows it cannot read with the reason and the source line number. Nothing is silently dropped.
Preview, then commit
Every import shows exactly what it would change before it changes anything. Committing is a separate, deliberate action, and the most recent import can always be taken back. Analysis never destroys data.
Analyze and hand over
Effective access, outliers, duty conflicts, role candidates and hygiene — then an executive PDF, a working Excel model, CSV and JSON, and a role export your IGA can import. The whole project is one portable file.
Client access data never leaves the machine
This is an architectural property, not a policy promise. Cleave runs as a local application bound to your own loopback interface. There is no account, no upload step, and no server of ours to breach — because there is no server of ours at all.
No telemetry, no analytics, no phone-home
The test suite blocks outbound network access by default, so a call that tried to leave would fail the build rather than ship.
AI is off by default, and optional forever
Every AI feature is opt-in and the product is fully functional without them. If you do enable one, all outbound context passes through a single enforced redaction step: populations go out as job-title and department distributions, never rosters or raw identifiers. Sending anything off your network requires an explicit confirmation naming the destination, and a local log records exactly what left.
Read-only against your estate
Cleave reads exports. It never connects to your directory and never touches provisioning, so it cannot change anyone's access.
One file, yours to delete
A project is a single portable file. Handing it to a client is a copy; disposing of client data is a delete.
Reads what your stack already emits
Prebuilt import profiles for the common exports, plus a mapping editor for everything else. Sources are neutral — cloud identity is just another export.
Run it against a real estate
Cleave is in active development ahead of its first release. If you run access reviews and want to try it against your own exports, get in touch.
Security model
Security
Cleave holds real enterprise access data, so its security model is built into how the product is structured rather than added as a policy layer on top.
Where your data lives
Entirely on the machine you run Cleave on. Each project is a single local file. There is no Cleave-operated server that receives, stores, or processes client access data, so there is no vendor-side breach surface for that data to sit in.
Network behaviour
The application serves its interface on your own loopback interface and validates the request host, so another site in your browser cannot reach it by re-pointing a hostname. Outbound network access is blocked by default in the automated test suite, which means an accidental call to the outside world fails the build rather than shipping.
The only outbound connections the product ever makes are:
- an AI provider you have explicitly configured and confirmed, and
- an offline-capable license check.
The AI redaction boundary
AI features are off by default and the product is fully functional without them. When enabled, all outbound context passes through a single enforced redaction step: holder populations are reduced to job-title and department distributions rather than rosters, sample rows are masked to shape hints, and identifier-shaped values — email addresses, distinguished names, directory identifiers — are stripped wherever they appear.
Choosing a provider endpoint outside your own network requires an explicit confirmation naming that endpoint. A local log records exactly what was sent, so you can inspect it rather than take our word for it. API keys are held in your operating system's credential store and never written into a project file, so handing a project to a client leaks neither keys nor another client's data.
Integrity of results
Analysis is deterministic: the same data with the same parameters produces the same findings, and every run records the parameters and reference date that produced it. Imports are the only path that modifies data, they are previewed before they commit, and the most recent one can be reversed. Analysis never deletes anything.
Reporting a vulnerability
If you believe you have found a security issue, please email security@cleavehq.com. Please include enough detail to reproduce the issue. We will acknowledge your report and keep you updated on our assessment.
Last updated 28 July 2026
Privacy
Draft. This policy describes how the product is actually built, but it has not yet been reviewed by legal counsel and should not be relied on as a binding statement until it has been.
The short version
Cleave runs on your machine. The identity and entitlement data you analyse with it stays there. We do not receive it, store it, or process it.
Data you analyse
Files you import, the project files Cleave creates, and every finding and report it produces are written to your own storage. They are never transmitted to us. We therefore cannot access, disclose, or recover them, and deleting a project file deletes that project's data.
Data we do collect
The application contains no analytics, no telemetry, and no crash reporting. We collect personal data only where you give it to us directly — for example, if you email us to request access, we hold your message and address in order to reply.
Optional AI features
If you enable an AI feature and configure a third-party provider, redacted context is sent to that provider under your own account and their terms. This is off by default and requires explicit confirmation. We are not a party to those requests and do not receive copies of them. Choosing a local provider keeps that traffic inside your own network.
Your rights
Where we do hold personal data about you — essentially, correspondence — you may ask us what we hold, ask us to correct it, or ask us to delete it. Write to privacy@cleavehq.com.
Changes
If this policy changes materially, the updated date above will change and the substantive change will be described here.
Last updated 28 July 2026
Terms
Draft. These terms are a working draft pending review by legal counsel. They are not yet a binding agreement.
What you are getting
A licence to install and use Cleave on the terms of your subscription or evaluation agreement. The software runs locally; we do not operate a service that holds your data, and so we cannot provide uptime, backup, or recovery commitments for it. Keeping your own backups of project files is your responsibility.
Acceptable use
Use Cleave only against data you are authorised to analyse. It is a read-only analysis tool intended for access review and audit work; you remain responsible for how its findings are interpreted and acted upon.
Findings are advice, not decisions
Cleave surfaces evidence and states its reasoning. It does not decide whether access is appropriate — that judgement is yours, and it depends on context the tool does not have. Nothing it produces is a certification of compliance with any standard or regulation.
Third-party providers
If you enable an optional AI feature, your use of that provider is governed by your agreement with them, not by these terms.
Warranties and liability
The software is provided without warranties beyond those that cannot be excluded by law. To the extent the law permits, our liability is limited to the fees you paid for the software in the twelve months before the claim.
Contact
Questions about these terms: legal@cleavehq.com.
Last updated 28 July 2026
Accessibility
We want Cleave to be usable by everyone who has to run an access review, including people using screen readers, keyboard-only navigation, magnification, or high-contrast settings.
What we are aiming for
Web Content Accessibility Guidelines (WCAG) 2.1 Level AA, for both this website and the application interface.
Where we are
This site is built to that target: it uses semantic landmarks and heading structure, is fully operable by keyboard with a visible focus indicator, provides a skip link, meets AA contrast in both light and dark themes, honours the reduced-motion system setting, and reflows to narrow viewports without horizontal scrolling. Its one diagram carries a text description of what it shows.
The application follows the same principles. It has not yet been through a formal third-party audit, so we describe this as our target and our current practice rather than as certified conformance. Where we find gaps, we fix them.
Known limitations
- Dense data tables in the application are usable by keyboard but have not yet been tested with every screen reader and browser combination.
- Some analysis views encode severity with colour and a text label; a small number still lean primarily on colour, which we are working through.
Tell us if something blocks you
If any part of this site or the application is difficult or impossible for you to use, please email accessibility@cleavehq.com and describe what you were trying to do. We treat access barriers as defects, and we will tell you what we intend to do and when.