KaryaFlow™ has not completed a SOC 2 audit. Our controls are built against the Trust Services Criteria and the audit is planned; ISO 27001 is scoped and on the roadmap; we make no HIPAA claim. This page summarises the controls we actually operate today.
Encryption
- AES-256 at rest.
- TLS 1.3 in transit.
- Customer-managed keys (CMK) via AWS KMS on Enterprise.
Access controls
- SAML 2.0 / OIDC SSO.
- SCIM 2.0 provisioning.
- Role-based and attribute-based access.
AI agent safety
Every agent action is logged in the audit log. Sensitive actions require human-in-the-loop approval. Tool access is scoped to the minimum privilege required.
Report a vulnerability
See our Responsible Disclosure page for the scope, submission channel, and safe-harbor terms.
