Legal / Kraylo Security & Trust
Kraylo Security & Trust
Last updated: 22 September 2026
Kraylo is a cloud-native, multi-tenant SaaS platform for field-sales operations. This page summarises current controls; it does not form a service-level agreement or guarantee absolute security.
Architecture and tenant isolation
Kraylo uses a Next.js application, Vercel hosting/CDN, Supabase managed PostgreSQL, authentication and storage, and Stripe for payments. All customer data is hosted in the European Union (Supabase, Germany region). Each tenant-owned record carries a company identifier. Database row-level security applies the tenant scope to reads and writes, so isolation is enforced at the database layer as well as in the application. A current list of sub-processors is maintained in our Sub-processor List.
Access and monitoring
Access follows least-privilege principles. Users are authenticated through managed identity services, and multi-factor authentication (MFA) is mandatory for all users. Permissions are restricted by role, and driver users are limited to their own records. Kraylo staff cannot sign into a customer workspace or read customer operational data such as sales, cash or reconciliation records. Support is provided only through a customer-approved session that automatically expires after 60 minutes and is limited to product and deal configuration. All support sessions, operational and security-relevant events, sign-ins and releases are logged for traceability. Dependencies are monitored for known vulnerabilities and security patches are applied promptly.
Encryption and payments
Traffic is protected using HTTPS/TLS. Managed cloud providers encrypt databases, storage and backups at rest; passwords are handled by Supabase Auth and are not stored in clear text by Kraylo. Stripe handles payment-card processing, so card data does not pass through Kraylo systems.
Resilience and change management
Current controls include daily automated database backups with seven-day retention, version-controlled code, controlled deployments and rollback capability. Changes are designed, reviewed, tested, version controlled, deployed, verified and monitored. Service availability is monitored continuously, and current and historical availability is published on our status page at https://statuspage.incident.io/kraylo.
Data rights
Customers remain the controller and owner of their operational data. On request and subject to the agreement, data can be exported in standard CSV or SQL formats and is returned or deleted at the end of the service term, subject to legal obligations. In the event of a personal data breach, Kraylo will notify affected customers promptly and, as set out in our Data Processing Addendum, within 48 hours of becoming aware, and will provide reasonable assistance so that customers can meet their own obligations to the Information Commissioner's Office (ICO) and to affected individuals, in line with UK GDPR.
Certifications
Kraylo currently does not claim ISO 27001 or Cyber Essentials certification. Those items are on its security roadmap. We will update this page if a certification is achieved.
Reporting security concerns
To report a suspected vulnerability or security concern, contact support@kraylo.co.uk. Please do not access, alter or exfiltrate data, disrupt the Services, or publicly disclose a vulnerability before allowing us a reasonable opportunity to investigate.