Security & Privacy

How Krater handles your data: EU hosting, encryption in transit and at rest, no training on your prompts, GDPR-compliant operations.

Built for Trust

Your data security matters. Krater is built on EU infrastructure with encryption in transit and at rest, no training on customer data, and GDPR-compliant operations.

Comprehensive security measures to protect your data at every layer.

End-to-End Encryption

All data is encrypted in transit and at rest using AES-256 encryption.

Data Privacy

Your conversations and files are private. We never train on your data.

Secure Infrastructure

Hosted on EU infrastructure (Supabase eu-west-1) with 99.9% uptime.

Compliance Ready

GDPR and CCPA compliant. We operate the practices these frameworks require — no training on customer data, encryption everywhere, DPAs available.

Access Controls

Role-based permissions and team management for secure collaboration.

Secure Authentication

SSO, 2FA, and enterprise identity provider integration available.

Our Security Commitments

We're committed to maintaining the highest standards of security and transparency.

  • We never sell your data to third parties
  • Your prompts and files are not used to train AI models
  • Data is automatically deleted on account closure
  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Customer data hosted in the EU (Supabase, eu-west-1)
  • Transparent data handling — see our policies for the full picture

Global Security Standards

Our infrastructure is designed to meet the most stringent security requirements worldwide.

How we protect your data

We don't claim certifications we haven't earned. Here's what's actually true today — the practices and regulations we operate under.

Operationally GDPR-compliant: DPA on request, data export and deletion, data minimization by default.

We honor California Consumer Privacy Act rights for US-based users.

Enterprise AI workspace · Developer API documentation · Krater pricing