Trust

    Security & trust

    Klearyon stores strategic work product for brands and teams. The controls below describe how we protect it.

    Last updated: June 16, 2026

    Encryption

    All traffic is encrypted in transit with TLS 1.2+. Project data, user records, and secrets are encrypted at rest. Third-party API keys you supply (e.g. OpenAI) are stored encrypted and never returned to the client after save.

    Authentication & access

    Email/password and Google sign-in, with leaked-password protection enabled (passwords checked against the Have I Been Pwned database during signup and password changes). Two-factor authentication (TOTP) and SSO (SAML / Google Workspace) are on the enterprise roadmap.

    Row-level security

    Every database table enforces row-level security policies. Users can only read and write data they own or have been explicitly granted access to. Security-definer functions are scoped and audited.

    Audit log

    Security-relevant actions — sign-in, password change, sharing changes, member invites, exports, deletions — are recorded in an append-only audit log with actor, IP, user-agent, and timestamp.

    Share-link controls

    Public share links are optional and per-view (Strategy Hub, Onboard, One-Pager). Owners can require a password and revoke at any time. Link expiration and view tracking are rolling out next.

    Data residency & sub-processors

    Infrastructure: Supabase (database, auth, storage) and Lovable (hosting). AI processing: OpenAI and Google. Customer content is never used to train models. Region disclosures are available on request for procurement reviews.

    Incident response

    Critical security incidents are triaged within one business day and communicated to affected workspace owners by email. We will issue a post-incident summary for any event involving customer data.

    Responsible disclosure

    Found a vulnerability? Email security@klearyon.com with steps to reproduce. We will acknowledge within two business days, investigate, and credit researchers who report in good faith.

    Enterprise security questionnaires

    Procurement teams can request a security overview, sub-processor list, and data-flow diagram by contacting security@klearyon.com. SOC 2 readiness work is underway.