Security

We take the security of your customer data seriously. Here's how Klyra protects your organization at every layer.

Encryption

All data is encrypted in transit and at rest.

  • TLS 1.3 for all data in transit
  • AES-256 encryption for data at rest (managed by Supabase/AWS)
  • API keys and secrets stored with application-level encryption
  • Webhook payloads verified with HMAC signatures

Multi-Tenant Isolation

Your data is strictly isolated from other organizations.

  • Every database query is scoped by organization ID
  • Triple-layered isolation: auth session, middleware, and database query filtering
  • Row-Level Security (RLS) policies on all tenant-scoped tables as defense-in-depth
  • Supabase Realtime uses broadcast channels (no direct database subscriptions from clients)

Authentication & Access Control

Enterprise-grade authentication powered by Clerk.

  • Authentication via Clerk (SOC 2 Type II certified)
  • Role-based access control: Owner, Admin, Member, Viewer
  • Session management with automatic expiry
  • HMAC verification for widget authentication
  • API key authentication for integrations with scoped permissions

Infrastructure

Hosted on trusted, secure cloud infrastructure.

  • Application hosted on Coolify (self-managed) with Docker containers
  • Database: Supabase (PostgreSQL) with automated backups
  • Redis: Managed instance for job queues and caching
  • CDN and DDoS protection via Cloudflare
  • Automated SSL certificate management

Data Handling

Responsible data practices from day one.

  • Customer data stored in PostgreSQL with point-in-time recovery
  • Database backups retained for 30 days
  • File attachments stored with signed URLs (time-limited access)
  • AI processing uses privacy-preserving models (no training on your data)
  • Data export available via API and CSV export tools

GDPR & Privacy

Built with privacy regulations in mind.

  • Data Processing Agreement (DPA) available on request
  • Right to access: export all your organization's data at any time
  • Right to deletion: full data purge available via Settings or on request
  • Contact data anonymization tools for compliance workflows
  • Privacy policy and terms of service publicly available

Application Security

Security best practices built into every layer.

  • Content Security Policy (CSP) headers with strict-dynamic
  • CSRF protection on all state-changing operations
  • Input validation with Zod schemas on every API endpoint
  • SQL injection prevention via parameterized queries (Drizzle ORM)
  • XSS prevention with DOMPurify sanitization
  • Rate limiting on authentication and public API endpoints

Monitoring & Incident Response

We monitor our systems and respond quickly to issues.

  • Error tracking with Sentry (real-time alerting)
  • Structured logging with correlation IDs for rapid debugging
  • Health check endpoints for all worker processes
  • Graceful shutdown handling to prevent data loss during deploys
  • PostHog analytics for product usage (no PII collection)

Security Roadmap

We're continuously improving our security posture. Planned initiatives:

  • SOC 2 Type I certification (in progress)
  • BYOK (Bring Your Own Key) for AI model providers
  • SAML SSO for enterprise customers
  • Penetration testing by third-party auditor

Have security questions? Need a DPA or security questionnaire completed?

[email protected]