Security overview
How we hold your drawings, your rates, and the record of who approved what.
Principles
- One wall per company. Your workspace is isolated. Another client cannot see your drawings, rates or records.
- Your work is not training data. We do not train models on client artifacts. Category tuning uses data we own or have written permission to use.
- Every action is attributable. Who asked, who signed, what ran, what it cost. The record is append-only.
- Least access. Our engineers do not browse client workspaces. Support access is time-bound, requested, and logged.
In transit and at rest
Traffic is served over TLS. Artifacts and records are encrypted at rest by the storage layer. Secrets sit in a managed store, never in source.
Access and accounts
Roles cover who can hand over work, who can approve it, and who can read the record. Approval rights cannot be given to the AI.
Reporting a problem
Write to security@kriyaetive.com. See responsible disclosure for what we promise in return.
Note: this page describes our current practices as a small team, not an audited programme. We hold no SOC 2 or ISO 27001 certification and will not imply otherwise. Ask us for the current control list before you commit.