Trust
Security & trust
Klearyon stores strategic work product for brands and teams. The controls below describe how we protect it.
Last updated: June 16, 2026
Encryption
All traffic is encrypted in transit with TLS 1.2+. Project data, user records, and secrets are encrypted at rest. Third-party API keys you supply (e.g. OpenAI) are stored encrypted and never returned to the client after save.
Authentication & access
Email/password and Google sign-in, with leaked-password protection enabled (passwords checked against the Have I Been Pwned database during signup and password changes). Two-factor authentication (TOTP) and SSO (SAML / Google Workspace) are on the enterprise roadmap.
Row-level security
Every database table enforces row-level security policies. Users can only read and write data they own or have been explicitly granted access to. Security-definer functions are scoped and audited.
Audit log
Security-relevant actions — sign-in, password change, sharing changes, member invites, exports, deletions — are recorded in an append-only audit log with actor, IP, user-agent, and timestamp.
Share-link controls
Public share links are optional and per-view (Strategy Hub, Onboard, One-Pager). Owners can require a password and revoke at any time. Link expiration and view tracking are rolling out next.
Data residency & sub-processors
Infrastructure: Supabase (database, auth, storage) and Lovable (hosting). AI processing: OpenAI and Google. Customer content is never used to train models. Region disclosures are available on request for procurement reviews.
Incident response
Critical security incidents are triaged within one business day and communicated to affected workspace owners by email. We will issue a post-incident summary for any event involving customer data.
Responsible disclosure
Found a vulnerability? Email security@klearyon.com with steps to reproduce. We will acknowledge within two business days, investigate, and credit researchers who report in good faith.
Enterprise security questionnaires
Procurement teams can request a security overview, sub-processor list, and data-flow diagram by contacting security@klearyon.com. SOC 2 readiness work is underway.