KaryaFlow
All docs
Security4 min read

Security and compliance

KaryaFlow security controls: encryption, SSO, audit logs, customer-managed keys, vulnerability reporting, and our certification status.

KaryaFlow™ has not completed a SOC 2 audit. Our controls are built against the Trust Services Criteria and the audit is planned; ISO 27001 is scoped and on the roadmap; we make no HIPAA claim. This page summarises the controls we actually operate today.

Encryption

  • AES-256 at rest.
  • TLS 1.3 in transit.
  • Customer-managed keys (CMK) via AWS KMS on Enterprise.

Access controls

  • SAML 2.0 / OIDC SSO.
  • SCIM 2.0 provisioning.
  • Role-based and attribute-based access.

AI agent safety

Every agent action is logged in the audit log. Sensitive actions require human-in-the-loop approval. Tool access is scoped to the minimum privilege required.

Report a vulnerability

See our Responsible Disclosure page for the scope, submission channel, and safe-harbor terms.