Security
At ClevAgent, security is foundational to our supervised terminal. Here's how we protect your data.
Infrastructure
- Hosting: Hetzner Cloud, Ashburn VA (US-East), an ISO 27001 certified datacenter
- Encryption in transit: Public clevagent.io traffic uses HTTPS.
- Local execution: Agent workspaces and the local gateway run on your workstation. The service may receive the account, usage, and agent telemetry described below.
Subprocessors
We use the following subprocessors to deliver our service:
| Subprocessor | Purpose | Data Processed | Location |
|---|---|---|---|
| Hetzner Cloud | Infrastructure hosting | Primary application database and service records | Ashburn, VA (US-East) |
| Cloudflare | CDN & DDoS protection | IP addresses, request metadata | Global edge |
| Stripe | Payment processing | Billing info (no card numbers stored by us) | US |
| Resend | Transactional email | Email address, notification content | US |
| Sentry | Error tracking | Error stack traces, request metadata | US |
| Optional sign-in | Email address, name | Global |
If you enable an optional alert channel (such as Telegram), alert notifications are delivered to that service using credentials you provide.
Authentication
- Credentials: Email + password authentication with bcrypt hashing. Password reset via secure email link.
- OAuth: Google OAuth sign-in available as an alternative to email/password. OAuth tokens are never stored; only the authenticated identity is used.
- Session security: HTTP-only, Secure, SameSite cookies
- Request validation: Browser authentication uses Auth.js CSRF protections, and cookie-authenticated backend mutations reject disallowed Origin or Referer values. API-key and signed webhook endpoints use separate authentication.
Data Protection
- Backups: Database backup jobs keep the latest 28 local backups. Encrypted offsite copies and email alerts operate when their required configuration is enabled. Failures are also logged.
- Access control: Multi-tenant data isolation limits project data to owners and explicitly invited members according to their role.
Responsible Disclosure
If you discover a security vulnerability, please email [email protected]. We will respond within 2 business days.
Payment Security
Payment processing is handled entirely by Stripe (PCI DSS Level 1 compliant). We never store credit card information.
Your Data at ClevAgent
What data do you collect?
We store account and session identifiers, plan usage, token counts, cost figures, settings, and service events needed to provide ClevAgent. Full chat transcripts are not sent as a standard payload. Service telemetry may include status messages, usage and cost data, prompt hashes, tool names, and up to 200 characters of tool arguments. ClevAgent may also send coaching summaries or evidence when coaching events are generated. Those fields can contain portions of commands or workspace content.
How long is service telemetry retained?
| Plan | Retention |
|---|---|
| Free | 7 days |
| Pro | 90 days |
| Max | 90 days |
Periodic agent telemetry, event records, cost logs, and daily reports older than your plan's retention window are automatically purged. Other account and service records are retained while needed to provide the service, maintain security and billing records, comply with law, or complete a deletion request.
How do I export my data?
Request a data export via [email protected]. Exports are delivered within 7 business days.
How do I delete my data?
Email [email protected] with your account email. We will delete all your data within 30 days and confirm by email.
Where is my data stored?
ClevAgent's primary application database is hosted on Hetzner Cloud in Ashburn, Virginia. The providers listed above may process or retain limited data for their stated purposes. Public clevagent.io traffic uses HTTPS.
Who can access my data?
Account owners and explicitly invited project members can access project data according to their assigned role. ClevAgent staff do not access customer data except when required to resolve a support issue you have raised.