Trust center

The artifacts your CISO will ask for.

Honest scope. We say implemented when the mechanism exists in the split proof, in progress when it is drafted, and planned when the work has a clear owner. Nothing is listed to fill a row, and every implemented claim names the mechanism that enforces it.

Isolation invariants

Four things the schema enforces, not the application.

The strongest isolation claims are enforced at the database schema level, not by application-layer filtering. These four invariants hold even if a future code bug forgets a WHERE clause.

Status

What is implemented, what is drafted, what is planned.

Each implemented item names the mechanism that enforces it. Each in-progress item names where you can get the current draft. Planned items have a clear owner with a timeline shared in the security review.

Legal artifacts

These documents are drafted with counsel and shared under NDA in the security review. Public versions land when the review process is complete.

Available under NDA during security review | Privacy policy, DPA, and subprocessor packet

Email security@karmanflow.com with your CISO checklist. We respond within two business days with the current artifacts.

Talk to security

Run a working session with engineers.

We open a 30-minute call, walk through the architecture and isolation model, answer your CISO checklist with current evidence, and share the security review packet under NDA.

Privacy choices

This controls app-managed marketing analytics: cookie-free Plausible, optional Cloudflare Web Analytics, and first-party event logs with session-only UTM attribution. The site works without it.

Read the privacy notice