klate
Security & data

Your work stays yours.

We take no ownership of your designs and use them only to run the service, never for advertising, analytics or model training.

Where we process data

  • EU

    Designs, branches, comments, versions

    Neon
  • EU

    Accounts and sign-in

    Neon Auth
  • EU

    The application and its scheduled jobs

    Vercel
  • EU

    Files and images you upload

    Cloudflare R2
  • EU

    Transactional email

    Resend
  • EU

    Payments and invoices

    Stripe
  • EU

    Error reports

    Sentry
  • US

    AI requests, while they are being answered

    OpenAI, Anthropic, via Vercel’s AI Gateway

An AI request carries your message and the design context the job needs. The answer comes back and is stored in the EU with everything else. Nothing reaches a model unless you ask for it. That includes your first design, which is drafted from the interview you fill in at sign-up.

Our assistant is optional. Authoring, branching, approvals and sharing can all run through your own AI agent over MCP instead, behind the same permission checks as the app, and in Claude the design itself renders in the chat. The model is then whichever one your agent uses, EU-hosted if that is what you run.

Nobody trains on your work.

Klate has no model of its own to train. OpenAI does not train on data sent through its API, and Anthropic does not train on the inputs or outputs of its commercial products.

We don’t leave that to the terms alone: every request Klate sends carries a no-training flag, and the gateway routes only to providers that have agreed to it. If none is available the request fails rather than quietly going somewhere that would.

Who holds it

Certifications as each provider publishes them, checked in September 2026.

Klate itself holds neither SOC 2 nor ISO 27001. We answer security questionnaires directly. Ask us for a provider’s report and we will help you get it.

  • Vercel

    Application, functions, scheduled jobs

    ISO 27001:2022SOC 2 Type 2EU-U.S. DPF
  • Neon

    Database, accounts, sign-in

    ISO 27001ISO 27701SOC 2 Type 1 and 2
  • Cloudflare

    Uploaded files, DNS

    ISO 27001:2022ISO 27701:2019ISO 27018:2019SOC 2 Type II
  • Stripe

    Payments and invoices

    PCI DSS Level 1SOC 1 and SOC 2 Type II
  • OpenAI

    AI requests, by default

    ISO 27001:2022ISO 27701:2019ISO 42001:2023SOC 2 Type 2
  • Anthropic

    AI requests, when selected

    ISO 27001:2022ISO 42001:2023SOC 2 Type 1 and 2

Encryption

We add no second layer of encryption of our own, and there is no bring-your-own-key option.

  • In transit

    Nothing travels in the clear, to us or between us and a provider, and your browser reaches the app over TLS 1.3. Browsers are told to refuse plain HTTP for two years at a time (HSTS, with includeSubDomains), and our content security policy stops the app being framed inside anyone else’s page.

  • At rest

    Neon, Cloudflare R2 and Vercel encrypt the data they hold for us on disk with AES-256.

  • Files you upload

    The storage bucket is private, with no public address to guess or pass around. When you open a file, the server checks you are allowed to and then signs a link (S3 SigV4) that stops working minutes later.

  • Passwords and tokens

    Your password is stored only as a salted hash. MCP tokens are stored as SHA-256 hashes, so a copy of our database holds no working token.

Send us the questionnaire.

You get the answers in writing.