Your work stays yours.
We take no ownership of your designs and use them only to run the service, never for advertising, analytics or model training.
Where we process data
- EU
Designs, branches, comments, versions
Neon - EU
Accounts and sign-in
Neon Auth - EU
The application and its scheduled jobs
Vercel - EU
Files and images you upload
Cloudflare R2 - EU
Transactional email
Resend - EU
Payments and invoices
Stripe - EU
Error reports
Sentry - US
AI requests, while they are being answered
OpenAI, Anthropic, via Vercel’s AI Gateway
An AI request carries your message and the design context the job needs. The answer comes back and is stored in the EU with everything else. Nothing reaches a model unless you ask for it. That includes your first design, which is drafted from the interview you fill in at sign-up.
Our assistant is optional. Authoring, branching, approvals and sharing can all run through your own AI agent over MCP instead, behind the same permission checks as the app, and in Claude the design itself renders in the chat. The model is then whichever one your agent uses, EU-hosted if that is what you run.
Nobody trains on your work.
Klate has no model of its own to train. OpenAI does not train on data sent through its API, and Anthropic does not train on the inputs or outputs of its commercial products.
We don’t leave that to the terms alone: every request Klate sends carries a no-training flag, and the gateway routes only to providers that have agreed to it. If none is available the request fails rather than quietly going somewhere that would.
Who holds it
Certifications as each provider publishes them, checked in September 2026.
Klate itself holds neither SOC 2 nor ISO 27001. We answer security questionnaires directly. Ask us for a provider’s report and we will help you get it.
- Vercel
Application, functions, scheduled jobs
ISO 27001:2022SOC 2 Type 2EU-U.S. DPF - Neon
Database, accounts, sign-in
ISO 27001ISO 27701SOC 2 Type 1 and 2 - Cloudflare
Uploaded files, DNS
ISO 27001:2022ISO 27701:2019ISO 27018:2019SOC 2 Type II - Stripe
Payments and invoices
PCI DSS Level 1SOC 1 and SOC 2 Type II - OpenAI
AI requests, by default
ISO 27001:2022ISO 27701:2019ISO 42001:2023SOC 2 Type 2 - Anthropic
AI requests, when selected
ISO 27001:2022ISO 42001:2023SOC 2 Type 1 and 2
Encryption
We add no second layer of encryption of our own, and there is no bring-your-own-key option.
In transit
Nothing travels in the clear, to us or between us and a provider, and your browser reaches the app over TLS 1.3. Browsers are told to refuse plain HTTP for two years at a time (HSTS, with includeSubDomains), and our content security policy stops the app being framed inside anyone else’s page.
At rest
Neon, Cloudflare R2 and Vercel encrypt the data they hold for us on disk with AES-256.
Files you upload
The storage bucket is private, with no public address to guess or pass around. When you open a file, the server checks you are allowed to and then signs a link (S3 SigV4) that stops working minutes later.
Passwords and tokens
Your password is stored only as a salted hash. MCP tokens are stored as SHA-256 hashes, so a copy of our database holds no working token.
Where the detail is
- Privacy noticeEvery processor, its legal entity, the legal basis, the transfer mechanism and each retention window. The binding document.
- Legal & ComplianceThe Art. 28 DSGVO data processing agreement, the service description, the price list and every other document, searchable.
- StatusLive availability of the application, measured from outside by an independent monitor.
Send us the questionnaire.
You get the answers in writing.

