Contents
1. Architecture and data flow
Karez connects only to the systems of record you select and authorize, using credentials and permission scopes you grant. There is no default connection to anything.
From those systems Karez reads the records they already hold, and builds an operational memory — an index of how work actually moves through your organization. Where that memory lives, how long it is kept, and who can query it are all customer-configured.
[Add: the actual data flow — ingestion path, where processing happens, where derived artifacts are stored, whether anything transits or is stored outside your primary region. A diagram belongs here.]
2. What Karez does not do
Karez is not an employee-monitoring product. Specifically, Karez does not:
- record or transcribe calls;
- ingest chat or messaging content for monitoring purposes;
- capture screens or keystrokes;
- collect biometric identifiers — voice, face, gait, or keystroke biometrics;
- produce individual employee performance scores or rankings.
[Verify every line, edit to match reality, then delete this note. Accuracy is the entire value of this section.]
3. Agent action boundaries
This is the section most security reviewers reach for first when a product takes autonomous action, and most vendors do not have one.
- Scope of authority. Each agent's authority is defined by the systems you connect it to, the credentials and permission scopes you grant, and the workflows and action types you enable. Agents operate within that scope.
- Write access is explicit. An agent has write, modify, or delete permission in a system only where you have granted it. [Describe how scopes are surfaced and constrained in the product UI.]
- Approval gates. You choose which actions require human approval before execution. [Describe the mechanism and its defaults. State plainly if this is not yet shipped.]
- Reversibility. [State honestly which action types are reversible and which are not. Do not overstate — irreversible actions in an ERP are the risk buyers care about.]
- Audit log. Every agent action is logged with the acting agent, the triggering event, the target system, the action performed, the timestamp, and the approving user if any. Logs are exportable in a machine-readable format. [Confirm retention period; must match the DPA.]
- Emergency stop. You can suspend any agent, or all agents, at any time from the product, with immediate effect. [Confirm this control exists before publishing.]
- Agent credentials are scoped and rotated separately from human credentials. [Confirm.]
4. Encryption
[Name the algorithms and versions — e.g. TLS 1.3 in transit, AES-256 at rest — and name which stores are covered: primary database, object storage, backups, logs, vector indexes, and derived artifacts. Listing only "the database" is the gap reviewers find.]
5. Hosting and subprocessors
Karez is hosted on [provider, region]. The table below lists every subprocessor with access to customer data.
| Entity | Service | Data categories | Region | Transfer mechanism | Retention & training posture |
|---|---|---|---|---|---|
| [Fill in. Include infrastructure providers and, in their own clearly labelled group, AI model providers — named individually, scoped per feature where applicable. The last column is the one nobody else publishes: state each provider's retention window and whether they train on our data. It is the single cheapest differentiator on this page.] | |||||
Change notice. We give [30] days' advance notice by email to your designated contact before adding a subprocessor, and you may object. Subscribe at [email protected]. If we cannot offer a reasonable workaround, you may terminate the affected service with a pro-rata refund of prepaid fees.
6. Access controls
- Least-privilege access, reviewed [cadence].
- MFA required for all Karez staff on all systems handling customer data. [Confirm.]
- Offboarding: access revoked within [period] of departure.
- Who at Karez can access customer data, and when. [State the roles, the break-glass conditions, whether access is logged, and whether those logs are available to you on request. Reviewers ask this specifically.]
- SSO / SCIM. [State what ships today and what is dated roadmap. Never present-tense something that ships next quarter. If SSO is planned to sit behind an enterprise tier, note that buyers increasingly read SSO paywalls as a negative signal.]
7. Tenant isolation
[This is the #1 AI-specific question in enterprise security review. State the actual isolation model, and specifically whether operational memory, embeddings, and model context are isolated per tenant, and that no customer's data influences another customer's outputs. "Multi-tenant with logical isolation" will not clear a review — be specific about the mechanism.]
8. Data residency
[Honest version, e.g.: "All customer data is currently stored in US-East. EU residency is on our roadmap and is not available today." Then state separately whether inference routes outside that region — customers increasingly ask, and silence reads as evasion.]
9. Retention and deletion
Retention is customer-configured per data class. On request or on termination, Karez deletes customer data and purges the derived artifacts built from it — embeddings, vector indexes, extracted graphs, operational memory, cached model context, and prompt and completion logs — within [N] days, with written confirmation on request.
Backups are included, with a maximum lag of [period] before expiry.
[BLOCKING: this commitment must be technically deliverable before it is published, and the number must match the DPA exactly. Publishing two different deletion figures in two documents is a defect reviewers find immediately.]
10. Incident response
Karez maintains a documented incident response plan with defined roles and escalation paths. [Confirm it exists before saying this.] In the event of a security incident affecting your data, we will notify your designated contact without undue delay and no later than [N] hours after we become aware of it.
We do not currently publish a status page. During beta, incidents and service disruptions are communicated directly to affected customers by email.
11. Vulnerability disclosure
We welcome good-faith security research on Karez-owned properties.
Authorization
If you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorized, we will work with you to understand and resolve the issue quickly, and Karez will not recommend or pursue legal action related to your research. Should legal action be initiated by a third party against you for activities that were conducted in accordance with this policy, we will make this authorization known.
Scope
In scope: [list Karez-owned domains and properties]. We specifically welcome reports of prompt injection, agent-action abuse, and tool-call manipulation.
Out of scope — and not authorized: any customer environment or connected third-party system, including customer data warehouses, ERP, TMS, ticketing, and document stores. Karez cannot authorize testing against systems it does not own. Any service not expressly listed above, including any connected services, is excluded from scope and is not authorized for testing.
Not authorized: denial of service, physical testing, and social engineering.
Guidelines
- Notify us promptly after discovering a real or potential issue.
- Avoid privacy violations, degradation of user experience, and destruction of data.
- Use exploits only to confirm a vulnerability's presence — never to exfiltrate data, establish persistence, or pivot to other systems.
- If you encounter sensitive data, stop and notify us immediately. Do not retain it.
- Allow reasonable time for remediation before public disclosure.
What you can expect from us
Acknowledgment within 3 business days. Progress updates as we work the issue, and credit for the finding if you want it.
Karez does not currently operate a paid bug bounty program.
Report to [email protected]. Anonymous submissions are accepted. This policy is version [1.0], dated [date], and is also published at /.well-known/security.txt.
12. Certifications
Karez does not currently hold a SOC 2 report, an ISO/IEC 27001 certificate, or an ISO/IEC 42001 certificate. We began SOC 2 Type II readiness work in [month/year] and expect our first observation window to run [range]. We will publish the report here when it is issued, and we will make it available under NDA at that time.
Our AI governance program is designed with reference to the control structure of ISO/IEC 42001 and the NIST AI Risk Management Framework; we are not certified against either standard and do not claim to be.
Nothing on this page should be read as a representation that Karez holds any third-party certification or attestation.
[If the CSA STAR Level 1 (CAIQ) self-assessment has been submitted — it is free and produces a public registry listing — link it here. It answers roughly 250 questionnaire items publicly and is the highest value-per-dollar item available before SOC 2.]
13. What Karez helps you meet
Separate from Karez's own certification status, the platform provides functionality customers can configure and operate to support their own obligations — for example agent action logging and export for supervisory and recordkeeping requirements, approval gates for human-oversight requirements, per-tenant retention and deletion controls, and subprocessor transparency for vendor-management programs.
These are product capabilities, not claims about Karez's accreditations. [Expand with the specific regimes your buyers actually raise. Keep the distinction between "what we hold" and "what we help you meet" explicit — conflating them is the classic overstatement.]
14. Security contact
[email protected] — monitored, acknowledged within 3 business days.
For security questionnaires, our DPA, or documentation under NDA, contact [email protected].