Security at Klusko: where your data lives and who can see it
Where your company’s tasks, messages and files are stored, how they’re kept apart from everyone else’s, and what we don’t have yet.
Your tasks, messages and files are stored in the EU, in Frankfurt. We use Supabase as our database provider, which runs Postgres on Amazon Web Services. The full list of companies that process data for us is on the subprocessors page.
How your data is kept apart
Every company on Klusko shares the same database, so the question that matters is what stops one company reading another’s rows. Row-level security does. It’s a feature of Postgres that checks every request against rules in the database itself. If someone at another company somehow built a request for your project’s tasks, the database would return nothing, because the rule says those rows belong to your company and they don’t. The check happens in the database rather than only in our app code, so a mistake in one screen of the app is far less likely to show you anything that isn’t yours.
Encryption and passwords
Everything between your browser or phone and our servers travels over TLS, and the app is only served over HTTPS. Data is also encrypted at rest on our database provider’s storage.
Passwords are handled by Supabase Auth. They’re stored hashed, and nobody at Klusko can see them. If you forget yours, nobody here can look it up for you.
Who can see what
There are two roles. The Admin is whoever created the company account, and admins invite people by email and can disable them, for example on someone’s last day. Members work in the company’s workspaces, projects and channels, and they don’t see private channels they haven’t been added to.
Guest isn’t a third role. It’s what someone becomes in a workspace when you add them to one of its projects without adding them to the workspace itself. In the app they see only the projects you’ve added them to. They can still read your public channels, and you can add them to private channels or direct messages, so if you bring in a client to approve artwork, keep the team’s own talk about that client in a private channel.
The row-level security described above keeps companies apart. It isn’t what decides which projects a guest sees inside your account.
Backups
Our database provider takes daily backups. They’re there so we can recover from a serious problem, like a failed disk or a bad mistake on our side. They aren’t a self-serve restore button, though: you can’t roll your own account back to last Tuesday.
What we do with your data
We don’t sell it. Not to anyone, for any reason. We also don’t use your tasks, messages or files to train AI models, ours or anyone else’s. Klusko has no AI features, so there’s nothing to feed them to anyway. Our privacy policy has the details, and if you need a data processing agreement for your own GDPR records, it’s on the DPA page.
What we don’t have yet
We don’t hold SOC 2 or ISO 27001 certification. If your procurement process needs either of those, we’re not the right choice for you yet, and we’d rather you found that out here.
There’s no single sign-on (SSO or SAML) either, so everyone signs in with their own email and password. And customers can’t see audit logs of who did what in their account. Those are all fair things to want. Bigger tools have them, and if you’re a 40-person firm with an IT manager, you’ll probably miss them sooner than a team of six would.
Reporting a vulnerability
If you think you’ve found a security problem in Klusko, email security@klusko.com with what you found and the steps to reproduce it. Please give us a reasonable chance to fix it before telling anyone else, and don’t access or change data that isn’t yours while you test. We’ll reply to let you know what happens next.