Our approach
KaryaFlow treats identity, tenant isolation, auditability and recovery as core product requirements. These are implemented control families, not a certification, warranty or substitute for deployment-specific security review.
Identity and sessions
Password controls, short-lived access tokens, protected refresh sessions and optional multi-factor verification reduce account risk.
Tenant and role boundaries
Workspace membership and role checks are intended to keep business records within their authorised tenant and function.
Data protection
The deployment contract requires encrypted transport, protected secrets and private object storage; operators must validate those controls in their own environment.
Audit and monitoring
Security-relevant and important business actions have audit paths, but operators remain responsible for monitoring and retention.
Continuity and recovery
Backup, health-check and recovery tooling is included; each operator must run and retain successful recovery evidence.
Secure product design
Visible session controls, inline validation and clear warnings help users recognise and correct risky account activity.
Your role in security
- Use a unique password and enable multi-factor verification when available.
- Do not share accounts. Invite each colleague with the minimum role they need.
- Review active sessions and remove access promptly when a person changes roles or leaves.
- Verify bank details and payment instructions through a trusted second channel.
- Keep exported reports and downloaded evidence in approved business storage.
- Report unexpected prompts, access or changes immediately.
Report a security concern
security@karyaflow.com is reserved for private reports, but its receipt path is not yet release-verified and must not be relied on for confidential disclosures. A verified private channel must be published before the first supported public release.
Until then, do not send passwords, authentication codes, complete payment credentials, personal data or unpublished vulnerability details to that address, and do not publish an unpatched vulnerability. Do not access or alter another person's data while testing.
Incident response
No provenance-cleared release is currently supported. For a future supported release, the policy is to assess credible reports, contain risk, preserve evidence, remediate confirmed defects and publish safe upgrade guidance.
This is a project-level maintenance commitment for supported versions, not individual incident response, a bug bounty or an SLA. Self-hosted operators retain responsibility for their own incidents and notifications.
Privacy and legal information
Security supports privacy but does not replace it. Read the Privacy Notice for data handling and the Terms of Service for account responsibilities.