Clikta
Security

Your data is safe with us

Security isn't an afterthought at Clikta — it's built into every layer of our infrastructure. EU-hosted, encrypted, and GDPR compliant by design.

🔒

Encryption at rest

All data — including screenshots and recordings — is encrypted using AES-256. Your content is unreadable without your credentials.

🔐

Encryption in transit

All communication between your browser, the Chrome extension, and our servers uses TLS 1.2 or higher. No plaintext transmission.

🇪🇺

EU-only infrastructure

All Clikta infrastructure runs on servers in the European Union (Germany). No personal data is ever stored or processed outside the EU.

🛡️

Passwords never stored

Passwords are hashed with bcrypt (12 rounds) before storage. We cannot recover your password — only you can reset it.

🔑

Access control

Role-based permissions ensure workspace data is isolated. Members can only access their own workspace. Sys admin access is strictly controlled.

📋

Audit logs

Critical actions (login, data access, publishing) are logged with timestamps and IP addresses. Logs are retained for 90 days.

🔄

Automated backups

Database backups run daily and are retained for 30 days. Backups are encrypted and stored in a separate EU location.

🔍

Regular security reviews

We conduct regular code reviews and dependency audits. Critical vulnerabilities are patched within 24 hours of discovery.

Responsible disclosure

If you discover a security vulnerability in Clikta, please report it responsibly to [email protected]. We will acknowledge receipt within 24 hours, work to resolve the issue promptly, and credit researchers who report valid vulnerabilities.

Please do not disclose vulnerabilities publicly before we've had a reasonable opportunity to address them.