Your strategy is sensitive.
We treat it that way.
Gevara is built on enterprise-grade infrastructure with encryption, strict access controls, and a simple promise: your data is never used to train AI models.
Encryption everywhere
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256) across our database and storage. There is no unencrypted path to your data.
Your data never trains AI models
Reports run on enterprise AI APIs (Anthropic, OpenAI, Google). Content sent for inference is not used to train their models. Your strategy stays yours.
Identity & access
Authentication is handled by Clerk with optional SSO/SAML and multi-factor auth. Role-based access (Owner, Admin, Member) governs every action.
Tenant isolation
Every record is scoped to your organization. Workspaces are logically isolated so one customer can never read another's data.
Auditability
Key actions — membership changes, billing, exports — are recorded in an audit trail so you always know who did what, and when.
Hardened infrastructure
Hosted on SOC 2-compliant infrastructure (Vercel, Neon) with automated backups, isolated environments, and least-privilege service access.
Compliance
We are transparent about where we are. Here is the honest current state — no inflated badges.
Built on SOC 2-compliant infrastructure; our own audit is underway.
Data-processing practices follow GDPR principles; a DPA is available for enterprise customers.
We never store card data — all payments are handled by Stripe (PCI DSS Level 1).
Signed DPA available on request for Business and Enterprise plans.
Subprocessors
The third parties that help us run Gevara. Every one is bound by data-protection obligations.
| Provider | Purpose |
|---|---|
| Vercel | Application hosting & edge network |
| Neon | PostgreSQL database (encrypted) |
| Clerk | Authentication, SSO/SAML, MFA |
| Stripe | Payments (PCI DSS Level 1) |
| Anthropic | AI inference (Claude) |
| OpenAI | AI inference (fallback) |
| AI inference (fallback) | |
| Resend | Transactional email |
| UploadThing | File storage |
| PostHog | Product analytics |
Responsible disclosure
Found a vulnerability? We want to hear from you. Email our security team and we will respond promptly — we credit responsible researchers.