Security approach
KaryaFlow treats identity, tenant separation, permissions, audit history, protected secrets, private storage and recoverability as core product responsibilities. Security also depends on the way each environment and connected provider is configured and operated.
Product design controls
- Authenticated sessions and role-aware permissions.
- Workspace and branch context applied to business operations.
- Audit paths for important actions and decisions.
- Protected configuration for secrets and provider credentials.
- Backup, health and recovery tooling for operators.
- Visible validation, failure and recovery states for users.
What users should do
- Use a unique password and enable multi-factor verification when available.
- Never share accounts; invite each colleague with the minimum role required.
- Remove access promptly when responsibilities change.
- Verify payment instructions through a trusted second channel.
- Protect downloaded reports and documents.
What an operating agreement must define
A future Self-Managed or Evlyr agreement must identify responsibility for capacity, patching, network controls, identity, secrets, monitoring, backup retention, restore exercises and incident response. This page does not create a security warranty or managed-service commitment.
Report a concern
If you notice unexpected access or behaviour, stop the affected action, preserve relevant details and contact your workspace administrator. General security concerns can be raised through the KaryaFlow contact page; do not include passwords, authentication codes, payment credentials or confidential records.