Trust Center
How we protect what you trust to us.
Security posture, compliance status, subprocessors, and the trust documentation your InfoSec team needs to sign off.
Security posture
Encryption in transit
All public traffic to the platform travels over TLS 1.2 or higher with HSTS enforced. Internal service-to-service communication is encrypted.
Encryption at rest
Customer data is encrypted at rest in the production database. Backups are encrypted using managed keys.
Access control
Role-based access. Server-side admin gates on every protected route. JWT-backed sessions with short expirations.
Row-level security
Postgres-style row-level security policies on every customer-owned table. The client never holds the service role key.
Rate limiting
Per-IP token-bucket rate limiting on every public API route. Protects against abuse and runaway costs.
Input sanitization
SSRF protection, private-network blocking, and AWS metadata endpoint protection on every domain input.
Audit logging
Every tool run, gate decision, and admin action is logged with timestamp, user, and result. Exportable for compliance review.
Human-in-loop gates
Customer-facing, financial, and irreversible actions are gated by the agent accountability system. Encoded in code, not in policy.
Compliance status
- In progress
SOC 2 Type I readiness
Targeted Q3 2026. Self-assessment underway with policy and control documentation.
- Planned
SOC 2 Type II
Targeted 2027 following Type I report and twelve months of observation period.
- Active
GDPR processor commitments
Standard Contractual Clauses and a Data Processing Addendum available on request.
- Active
CCPA and CPRA compliance
Consumer rights honored, no sale of personal information.
- Planned
ISO 27001
Under evaluation for 2027.
- Planned
HIPAA Business Associate Agreement
Available on request for Custom tier customers in healthcare-adjacent industries.
Subprocessors
The third-party services KAIRO uses to deliver the platform. Customer notice will be given at least thirty days before any new subprocessor is engaged for production use.
Documentation
Security architecture
Six security layers with the specs.
ReadData Processing Addendum
GDPR Article 28 commitments and Standard Contractual Clauses.
ReadPrivacy Policy
What we collect, why, and your rights.
ReadTerms of Service
Agreement governing platform usage.
ReadSources and methodology
Where the intelligence comes from.
ReadService Level Agreement
Uptime, support response, and service credits.
ReadNeed more
Custom Security and Compliance Review.
Need a written security posture for your InfoSec review, a data flow diagram, or a gate-category mapping to your internal policy? See the Service package.
Security and Compliance Review