KLEVRManagement

Security at KLEVR Management

Last updated: 21 September 2026

KLEVR holds the working data of bands, managements, promoters and rental companies: who is on which gig, where and when, travel details, fees. This page explains where that data lives, how it is protected, and who else handles it on our behalf. For the legal terms of processing, see the data processing agreement.

Where your data lives

The database, uploaded files and the login service run at Supabase in the AWS region eu-west-1 (Ireland). The application runs on Vercel with its server functions in Dublin. Backups stay in the same region. Nothing is stored on laptops or office servers. The company behind KLEVR Management, KLEVR AUDIO LLC, is established in the United States; the data stays in the EU, and customers in the EU are covered by the Standard Contractual Clauses built into the data processing agreement.

Encryption

Every connection uses TLS, and browsers are told to use it always (HSTS). Data is encrypted at rest by our providers. Passwords are stored only as salted hashes by the login service; KLEVR never sees them. Card details go straight to Stripe or Apple and never reach our servers.

Keeping teams apart

Every table in the database carries row level security: the database itself refuses to return a row that belongs to another team, whatever the application asks for. The team you are working in is a hard boundary. Guests invited to a single gig see that gig and nothing else. A shared client link shows only the sections the team chose to share, and can be switched off at any time.

Accounts and access

  • Roles (admin, manager, member, guest) with per-person permissions that an admin controls.
  • Two-factor authentication with an authenticator app, available to every account and recommended for admins.
  • Password rules enforced at sign-up and on every change; changing a password requires the current one.
  • Account deletion from inside the app, with a typed confirmation, and a public deletion page for people without access.
  • Every action taken through the Claude connector on behalf of a person is written to an audit table under that person's name.

Backups and continuity

Supabase takes a physical backup of the database every day and keeps seven of them, with continuous write-ahead-log archiving in between. The application itself holds no state and can be redeployed from source in minutes. We monitor backup completion as part of our routine checks.

Monitoring and change control

The site and the database are checked every five minutes from outside, and the platform owner is alerted when a check fails or when the database runs short of headroom. Every version is built and type-checked automatically before it goes live. Dependencies are scanned for known vulnerabilities continuously, with fixes raised automatically.

AI features

Some teams use AI imports (a run plan into a schedule, a poster into a tour, a ticket into flights). Only when a person starts an import is that document sent to Anthropic's API to read it; the result comes back for the person to review before anything is saved. Under Anthropic's API terms the content is not used to train models. Nothing else in KLEVR is sent to an AI service.

Sub-processors

These companies process data for us. We tell customers with a data processing agreement before adding a new one.

ProviderPurposeLocation
SupabaseDatabase, file storage and login serviceAWS eu-west-1, Ireland
VercelHosting of the web application and its server functionsDublin, Ireland (edge network worldwide)
StripeSubscription payments (card details never touch KLEVR)EU and United States
AppleApp Store subscriptions and push notifications to iPhonesUnited States and EU
GooglePush notifications to Android phones, and venue lookup (Maps Platform)EU and United States
ResendTransactional email (invitations, reminders, account mail)United States and EU
AnthropicAI imports: reading a document a team uploads for importUnited States
AeroDataBox (via RapidAPI)Flight lookups by flight number and date, no personal dataEU

Providers outside the EU/EEA are used under the EU Standard Contractual Clauses or the EU-US Data Privacy Framework, whichever applies to them.

Incidents and vulnerability reports

If you believe you have found a security problem, write to hello@klevrmanagement.com. We answer within two working days and do not take action against good-faith reports. If personal data in KLEVR is ever exposed, we tell the affected teams without undue delay and at the latest within 72 hours of confirming it, with what happened and what we did.

Questions

Security questionnaires, a signed data processing agreement, or details for your own records: hello@klevrmanagement.com.