Your data is safe with us
Security isn't an afterthought at Clikta — it's built into every layer of our infrastructure. EU-hosted, encrypted, and GDPR compliant by design.
Encryption at rest
All data — including screenshots and recordings — is encrypted using AES-256. Your content is unreadable without your credentials.
Encryption in transit
All communication between your browser, the Chrome extension, and our servers uses TLS 1.2 or higher. No plaintext transmission.
EU-only infrastructure
All Clikta infrastructure runs on servers in the European Union (Germany). No personal data is ever stored or processed outside the EU.
Passwords never stored
Passwords are hashed with bcrypt (12 rounds) before storage. We cannot recover your password — only you can reset it.
Access control
Role-based permissions ensure workspace data is isolated. Members can only access their own workspace. Sys admin access is strictly controlled.
Audit logs
Critical actions (login, data access, publishing) are logged with timestamps and IP addresses. Logs are retained for 90 days.
Automated backups
Database backups run daily and are retained for 30 days. Backups are encrypted and stored in a separate EU location.
Regular security reviews
We conduct regular code reviews and dependency audits. Critical vulnerabilities are patched within 24 hours of discovery.
Responsible disclosure
If you discover a security vulnerability in Clikta, please report it responsibly to [email protected]. We will acknowledge receipt within 24 hours, work to resolve the issue promptly, and credit researchers who report valid vulnerabilities.
Please do not disclose vulnerabilities publicly before we've had a reasonable opportunity to address them.
