ClevAgent is not open yet. Purchases are not available while we finish the last work before launch.

ClevAgent
Trust

Security

Last updated: July 13, 2026

At ClevAgent, security is foundational to our supervised terminal. Here's how we protect your data.

Infrastructure

  • Hosting: Hetzner Cloud, Ashburn VA (US-East), an ISO 27001 certified datacenter
  • Encryption in transit: Public clevagent.io traffic uses HTTPS.
  • Local execution: Agent workspaces and the local gateway run on your workstation. The service may receive the account, usage, and agent telemetry described below.

Subprocessors

We use the following subprocessors to deliver our service:

SubprocessorPurposeData ProcessedLocation
Hetzner CloudInfrastructure hostingPrimary application database and service recordsAshburn, VA (US-East)
CloudflareCDN & DDoS protectionIP addresses, request metadataGlobal edge
StripePayment processingBilling info (no card numbers stored by us)US
ResendTransactional emailEmail address, notification contentUS
SentryError trackingError stack traces, request metadataUS
GoogleOptional sign-inEmail address, nameGlobal

If you enable an optional alert channel (such as Telegram), alert notifications are delivered to that service using credentials you provide.

Authentication

  • Credentials: Email + password authentication with bcrypt hashing. Password reset via secure email link.
  • OAuth: Google OAuth sign-in available as an alternative to email/password. OAuth tokens are never stored; only the authenticated identity is used.
  • Session security: HTTP-only, Secure, SameSite cookies
  • Request validation: Browser authentication uses Auth.js CSRF protections, and cookie-authenticated backend mutations reject disallowed Origin or Referer values. API-key and signed webhook endpoints use separate authentication.

Data Protection

  • Backups: Database backup jobs keep the latest 28 local backups. Encrypted offsite copies and email alerts operate when their required configuration is enabled. Failures are also logged.
  • Access control: Multi-tenant data isolation limits project data to owners and explicitly invited members according to their role.

Responsible Disclosure

If you discover a security vulnerability, please email [email protected]. We will respond within 2 business days.

Payment Security

Payment processing is handled entirely by Stripe (PCI DSS Level 1 compliant). We never store credit card information.

Your Data at ClevAgent

What data do you collect?

We store account and session identifiers, plan usage, token counts, cost figures, settings, and service events needed to provide ClevAgent. Full chat transcripts are not sent as a standard payload. Service telemetry may include status messages, usage and cost data, prompt hashes, tool names, and up to 200 characters of tool arguments. ClevAgent may also send coaching summaries or evidence when coaching events are generated. Those fields can contain portions of commands or workspace content.

How long is service telemetry retained?

PlanRetention
Free7 days
Pro90 days
Max90 days

Periodic agent telemetry, event records, cost logs, and daily reports older than your plan's retention window are automatically purged. Other account and service records are retained while needed to provide the service, maintain security and billing records, comply with law, or complete a deletion request.

How do I export my data?

Request a data export via [email protected]. Exports are delivered within 7 business days.

How do I delete my data?

Email [email protected] with your account email. We will delete all your data within 30 days and confirm by email.

Where is my data stored?

ClevAgent's primary application database is hosted on Hetzner Cloud in Ashburn, Virginia. The providers listed above may process or retain limited data for their stated purposes. Public clevagent.io traffic uses HTTPS.

Who can access my data?

Account owners and explicitly invited project members can access project data according to their assigned role. ClevAgent staff do not access customer data except when required to resolve a support issue you have raised.