Security & Trust

Your brand data is protected

How we store brand data, separate accounts, and work with AI providers.

Apply for Pilot

What this page covers

Eklipsa stores brand strategy: positioning, audience, voice, and visual direction. The sections below separate controls in the product from responsibilities that belong to Stripe, Supabase, Vercel, and the AI providers.

Current security posture

Production responses use HTTPS, HSTS, a content security policy, frame denial, and MIME sniffing protection
Organization roles and row-level security separate customer data between accounts
Stripe Checkout and the Stripe customer portal collect payment details. Eklipsa does not store full card numbers
Billing webhooks are accepted only after Stripe's signature check
Application functions run in Vercel US East (iad1). Database, auth, and files are in Supabase US East (us-east-1)
Automated tests cover tenant isolation and signed billing webhooks

This list describes controls in the product. It is not an audit report, and it is not an Eklipsa certification.

How we protect your data

Encryption

Visitors reach the site over HTTPS. In production the app sends HSTS, a content security policy, frame denial, and MIME sniffing protection. Supabase states that disks and backups are encrypted at rest with AES-256, and that its network traffic uses TLS 1.2 or newer.

Access controls

Sign-in is handled by Supabase Auth. Organization roles limit who on an account can view or change a brand. Database row-level security keeps one account's rows separate from another's.

Checks we run

Automated tests cover tenant isolation, privileged database functions, and signed billing webhooks. Those checks cover this product. They are not a third-party certification of Eklipsa.

AI data usage

Brand data powers Brand Intelligence inside your account. We do not use it to train, fine-tune, or improve third-party foundation models. Optional visual-style training sends the assets you select to fal.ai only when you start that step.

Where data is stored

Account, brand, and file data live in Supabase in one US East region (us-east-1). Application functions run on Vercel in US East (iad1). Supabase documents daily backups on paid plans. This page does not state a restore window or a second live database region.

If something goes wrong

The Privacy Policy describes how we notify affected people after a security incident involving personal information. Report a vulnerability to legal@eklipsa.ai.

How we handle AI and your data

Brand data powers Brand Intelligence inside your account. You keep ownership of what you submit.

You own your content

You retain ownership of content you create, upload, or submit. We do not sell personal information. The Privacy Policy lists the service providers that process data to run the product.

Accounts stay separate

Brand context in a request is limited to that account. One account's Brand Intelligence is not copied into another account's prompts.

Foundation models stay general

We do not use your brand data to train, fine-tune, or improve third-party foundation models. If you start optional visual-style training, the assets you select are sent to fal.ai to train a style model for that brand. That step runs only when you start it.

Export and delete

You can delete a brand from brand settings and delete your account from profile settings. You can export deliverables the product already exports, including a Brand Book as DOCX, and you can request a copy of personal information at legal@eklipsa.ai. We respond to emailed requests within 30 days. Deletion follows the retention policy. It does not instantly erase every backup.

Infrastructure providers

Certifications named here belong to that provider. Eklipsa does not claim those certifications for itself.

Payments

Stripe

Stripe is a PCI DSS Level 1 service provider. That certification belongs to Stripe. Card numbers are collected by Stripe. Eklipsa does not store full card numbers.

Database, auth, and files

Supabase

Supabase states that its platform is SOC 2 Type 2. That certification belongs to Supabase. Supabase states that disks and backups are encrypted at rest with AES-256, and that network traffic uses TLS 1.2 or newer.

AI providers

OpenAI, Anthropic, Groq, fal.ai, Gamma

Text features use OpenAI or Anthropic. In production those requests go through Vercel AI Gateway. Economy text models may be hosted by Groq through that gateway. Image and visual generation uses fal.ai. Deck generation uses Gamma when you run it. Content is sent when you use the feature.

Hosting

Vercel

Vercel hosts the application. Serverless functions run in US East (iad1). Vercel terminates HTTPS and provides platform DDoS mitigation. Those controls belong to Vercel.

Trust depends on clear safeguards and honest communication.

For full details, see our Privacy Policy and Terms of Service.

Common security questions

Protect the strategy you build

Apply for the Professional Pilot to evaluate Eklipsa with one client.

Apply for Pilot

One qualifying client. 30 active days after activation. 100,000 credits once. No credit card.