Security
We take the security of your customer data seriously. Here's how Klyra protects your organization at every layer.
Encryption
All data is encrypted in transit and at rest.
- TLS 1.3 for all data in transit
- AES-256 encryption for data at rest (managed by Supabase/AWS)
- API keys and secrets stored with application-level encryption
- Webhook payloads verified with HMAC signatures
Multi-Tenant Isolation
Your data is strictly isolated from other organizations.
- Every database query is scoped by organization ID
- Triple-layered isolation: auth session, middleware, and database query filtering
- Row-Level Security (RLS) policies on all tenant-scoped tables as defense-in-depth
- Supabase Realtime uses broadcast channels (no direct database subscriptions from clients)
Authentication & Access Control
Enterprise-grade authentication powered by Clerk.
- Authentication via Clerk (SOC 2 Type II certified)
- Role-based access control: Owner, Admin, Member, Viewer
- Session management with automatic expiry
- HMAC verification for widget authentication
- API key authentication for integrations with scoped permissions
Infrastructure
Hosted on trusted, secure cloud infrastructure.
- Application hosted on Coolify (self-managed) with Docker containers
- Database: Supabase (PostgreSQL) with automated backups
- Redis: Managed instance for job queues and caching
- CDN and DDoS protection via Cloudflare
- Automated SSL certificate management
Data Handling
Responsible data practices from day one.
- Customer data stored in PostgreSQL with point-in-time recovery
- Database backups retained for 30 days
- File attachments stored with signed URLs (time-limited access)
- AI processing uses privacy-preserving models (no training on your data)
- Data export available via API and CSV export tools
GDPR & Privacy
Built with privacy regulations in mind.
- Data Processing Agreement (DPA) available on request
- Right to access: export all your organization's data at any time
- Right to deletion: full data purge available via Settings or on request
- Contact data anonymization tools for compliance workflows
- Privacy policy and terms of service publicly available
Application Security
Security best practices built into every layer.
- Content Security Policy (CSP) headers with strict-dynamic
- CSRF protection on all state-changing operations
- Input validation with Zod schemas on every API endpoint
- SQL injection prevention via parameterized queries (Drizzle ORM)
- XSS prevention with DOMPurify sanitization
- Rate limiting on authentication and public API endpoints
Monitoring & Incident Response
We monitor our systems and respond quickly to issues.
- Error tracking with Sentry (real-time alerting)
- Structured logging with correlation IDs for rapid debugging
- Health check endpoints for all worker processes
- Graceful shutdown handling to prevent data loss during deploys
- PostHog analytics for product usage (no PII collection)
Security Roadmap
We're continuously improving our security posture. Planned initiatives:
- SOC 2 Type I certification (in progress)
- BYOK (Bring Your Own Key) for AI model providers
- SAML SSO for enterprise customers
- Penetration testing by third-party auditor
Have security questions? Need a DPA or security questionnaire completed?
[email protected]