KlirInvest is not authorised or regulated by the Financial Conduct Authority. KlirInvest is an educational analytics platform. It does not provide investment advice, recommendations, or portfolio management services. Educational purposes only.Educational analytics only — not investment advice.

Security at KlirInvest

We protect your financial data with the same rigour we'd want for our own. Here are the current controls and practices.

TLS 1.2+
AES-256 at rest
MFA available
Row-Level Security

Encryption

  • •TLS 1.2 or higher for all data in transit (HTTPS everywhere).
  • •AES-256 encryption at rest for the database, storage and backups.
  • •Broker connection keys encrypted with a dedicated key before storage.

Authentication & access

  • •Email + password authentication with password strength checks during sign-up.
  • •Optional multi-factor authentication (TOTP) for every account.
  • •Sign in with Google supported.
  • •Session-based access with automatic token refresh and revocation.

Data isolation

  • •Row-Level Security (RLS) enforced on every user-facing table.
  • •Tenant isolation for advisor and team accounts.
  • •Server-side authorisation checks on every privileged action.

Privacy & PII handling

  • •Personal data (name, email, IDs) is masked in admin views by default.
  • •We never sell your data and never share it with third parties for advertising.
  • •You can export or delete your account data at any time from Settings.

Audit & monitoring

  • •Admin actions are logged for audit and review.
  • •Authentication attempts and suspicious activity are recorded and rate-limited.
  • •Real-time uptime monitoring on our public status page.

Infrastructure

  • •Hosted using established infrastructure and payment/data providers that publish security and compliance documentation.
  • •Database backup and restore procedures are maintained through our hosting provider. Restore/PITR evidence is tracked internally before production launch.
  • •Edge functions sandboxed with least-privilege service roles.

Sub-processors

The processors below are named on our public pages. Additional recipient categories are listed by type and transfer location. The canonical version of this disclosure lives in our Privacy Policy.

Named sub-processors

  • •Supabase Inc. — Database, authentication, storage, and edge functions (USA)
  • •Stripe Inc. — Subscription billing and payment processing (USA)
  • •SnapTrade (Passiv Technologies Inc.) — Read-only brokerage account connectivity (holdings & transactions) (Canada / USA)
  • •Google LLC — Sign-in with Google; Gemini AI access via Lovable AI Gateway (USA)

Other recipient categories

  • •AI model providers — Generative AI responses for in-app analysis and chat (USA)AI providers process portfolio context to generate responses and are contractually prohibited from training models on KlirInvest data.
  • •AI search & news-intelligence providers — AI-assisted search across market and company news (USA)Contractually prohibited from training models on KlirInvest data.
  • •Market-data providers — Equity, ETF, and fundamentals data (USA)
  • •News-data providers — Financial news data (USA)

Specific provider identities are available to enterprise customers under NDA via hello@klirinvest.com. Individual users can request the specific recipients of their personal data at any time at hello@klirinvest.com.

Responsible disclosure

If you believe you've found a security vulnerability in KlirInvest, please report it to us privately so we can fix it before it's disclosed publicly.

  • •Email hello@klirinvest.com with details and reproduction steps.
  • •Please give us a reasonable time to respond before any public disclosure.
  • •Do not access or modify data that doesn't belong to you, or run automated scans against production.
  • •We acknowledge all good-faith reports and will credit researchers (with permission) once a fix is shipped.
Report a vulnerability

See also our Privacy Policy, Terms, and Status page.