Legal · Trust
Trust, Security & Compliance
Effective July 26, 2026
At Kloyya, protecting your information is fundamental to everything we build. We design our platform with security, privacy, and reliability at its core so you can confidently connect your work, collaborate with your team, and use AI responsibly.
This page explains how we secure your data and the principles that guide our platform.
01Our security principles
Everything we build follows these principles:
- Security by Design
- Privacy by Default
- Least Privilege Access
- Customer Data Ownership
- Transparent AI
- Continuous Improvement
These principles influence every feature, integration, and infrastructure decision we make.
02Infrastructure security
Kloyya is built on modern cloud infrastructure designed for reliability and security. Our platform uses trusted providers including:
- Supabase
- Vercel
- Resend
- Industry-leading AI providers
Infrastructure is monitored continuously and protected using multiple layers of security.
03Data encryption
We protect customer data using encryption throughout its lifecycle.
Data in transit. All communication between your device and Kloyya is encrypted using HTTPS/TLS.
Data at rest. Stored information is encrypted using industry-standard encryption technologies provided by our infrastructure partners.
04Authentication & access control
Kloyya protects user accounts using secure authentication systems. Security features include:
- Secure authentication
- Email verification
- Session management
- Access controls
- Role-based permissions
- Workspace isolation
- Secure password handling
We never store passwords in plain text.
05Workspace isolation
Every workspace is logically isolated from every other workspace. Users can only access information they are authorized to view. Our database policies enforce access controls to prevent unauthorized access across organizations and workspaces.
06AI security
AI should help you work smarter while respecting your privacy. Kloyya is designed so that:
- AI only processes information you authorize.
- Connected data remains under your control.
- AI responses are based on available context and connected sources.
- AI-generated content should be reviewed before making important decisions.
- Private workspace information is not used to train public AI models unless you explicitly opt in.
07Connected applications
Kloyya integrates with third-party applications to help you work from one place. We request only the permissions required to provide the features you enable. You can disconnect integrations at any time.
08Monitoring & threat detection
To protect our platform, we monitor for:
- Suspicious logins
- Unauthorized access attempts
- Abuse and spam
- Service interruptions
- Security anomalies
- Infrastructure health
Monitoring helps us detect and respond to potential security incidents quickly.
09Secure development
Security is built into our development process. We regularly:
- Review code
- Test new features
- Apply security updates
- Monitor dependencies
- Validate infrastructure changes
- Review access permissions
- Improve platform resilience
Security is considered throughout development — not only before release.
10Responsible AI
Kloyya is committed to responsible AI. Our goals include:
- Transparent AI assistance
- Reliable information retrieval
- User control over connected data
- Clear attribution where possible
- Continuous improvements to accuracy and safety
AI is designed to assist users, not replace professional judgment.
11Data ownership
Your data belongs to you. You retain ownership of the content you upload, create, or connect through Kloyya. We process your data only to provide the Services described in our Privacy Policy and Terms of Service. We do not sell customer data.
12Privacy
Privacy is a core part of our platform. We collect only the information necessary to operate and improve Kloyya. You remain in control of your connected accounts and may disconnect them or request deletion of your account in accordance with our Privacy Policy.
13Incident response
If we detect a security incident, our response includes:
- Investigation
- Containment
- Impact assessment
- Recovery
- User notification where required by applicable law
- Continuous improvements to prevent similar incidents
14Business continuity
We are committed to maintaining reliable service. Our operational practices include:
- Secure cloud infrastructure
- Backup and recovery processes
- Service monitoring
- Planned maintenance procedures
- Ongoing platform improvements
15Compliance
Kloyya is designed with privacy and security best practices in mind. As the platform grows, we will continue investing in compliance programs and recognized security standards appropriate for our customers and business. Our compliance efforts focus on:
- Data protection
- Privacy regulations
- Secure software development
- Risk management
- Access controls
- Auditability
- Responsible AI practices
As certifications become available, they will be listed here.
16Reporting security issues
If you believe you have discovered a security vulnerability, we encourage responsible disclosure. Please contact us with sufficient information to reproduce the issue.
Email: contactsupport@kloyya.com
We appreciate responsible security research and will investigate reported issues promptly.
17Contact
If you have questions about security, privacy, or compliance, please contact us.
Email: contactsupport@kloyya.com
Thank you for trusting Kloyya with your work.