KaryaFlow
Security

What we ship, and what we don't.

Most vendor security pages are a wall of certification badges. We are a young company and we have none of them yet, so this page says what actually exists — and names what does not.

Certification status

Stated plainly, because a buyer finding out during diligence is worse than a buyer finding out here.

SOC 2 Type II

Not certified — audit planned

Controls are built against the Trust Services Criteria. No audit has been completed and no report exists yet.

ISO 27001

Not certified — scoped

On the roadmap. Scoping is done; the certification process has not started.

HIPAA

No claim

We make no HIPAA claim. If you need it today, we are not the right vendor.

India DPDP Act, 2023

Built to it

Purpose limitation, consent records, deletion on request, and breach notification paths. This is our home regulation — we are headquartered in Jaipur.

Controls that exist today.

Encryption

AES-256 at rest, TLS 1.3 in transit. No customer data moves between services unencrypted.

Access control

Role-based access control with a single permission tree across every module, not one per module.

Identity

SSO via SAML and OIDC, with SCIM provisioning and de-provisioning. Available on Enterprise.

Customer-managed keys

Bring your own encryption keys on Enterprise plans, so revoking access is your decision, not a support ticket.

Agent audit log

Every action an AI agent takes is written to an immutable log — what it did, on whose authority, and against which record.

Approval gates

Agent actions that change data can require human approval before they commit. You choose which ones.

The part most vendors skip.

An AI agent that can write to your CRM is a user with credentials. It should be governed like one. In KaryaFlow an agent inherits the same permission tree as a human, cannot exceed the scope it was granted, and writes every action to the same immutable log your people write to.

Two questions are worth asking any vendor selling you agents, including us. Show me the log of what the agent did last week. Show me how I stop it doing something I have not approved. If either answer is a roadmap item, you are being sold a demo.

We wrote up the full model in AI agent security, the part vendors skip.

Common questions

Is KaryaFlow SOC 2 Type II certified?
No, and we will say so plainly until it is true. Our SOC 2 Type II audit is planned and our controls are built against the Trust Services Criteria, but no audit has been completed and no report exists. Any page claiming otherwise is out of date — tell us and we will fix it.
Is KaryaFlow ISO 27001 or HIPAA certified?
No. ISO 27001 is scoped and on the roadmap. We make no HIPAA claim at all. We would rather lose a deal over this than have you discover it during diligence.
What security controls exist today?
AES-256 encryption at rest and TLS 1.3 in transit, role-based access control, SSO via SAML and OIDC with SCIM provisioning, customer-managed encryption keys on Enterprise, an immutable audit log covering every AI agent action, and human approval gates on agent actions that change data.
How does KaryaFlow handle India's DPDP Act?
Our data handling is built against the Digital Personal Data Protection Act, 2023 — purpose limitation, consent records, deletion on request, and breach notification paths. We are an Indian company headquartered in Jaipur, so this is our home regulation rather than an export requirement. Ask us for specifics on data residency for your deployment.

Found something on this site that contradicts this page? That is a bug and we want to know. Report security issues through responsible disclosure.