Trust Current practices

Security overview

How we hold your drawings, your rates, and the record of who approved what.

Principles

In transit and at rest

Traffic is served over TLS. Artifacts and records are encrypted at rest by the storage layer. Secrets sit in a managed store, never in source.

Access and accounts

Roles cover who can hand over work, who can approve it, and who can read the record. Approval rights cannot be given to the AI.

Reporting a problem

Write to security@kriyaetive.com. See responsible disclosure for what we promise in return.

Note: this page describes our current practices as a small team, not an audited programme. We hold no SOC 2 or ISO 27001 certification and will not imply otherwise. Ask us for the current control list before you commit.