Security & trust

Answers for the person
who signs the risk assessment.

Identity, access, residency, auditability and agent behaviour — written plainly, because a security review should not require a discovery call.

Photo · Security team, operations centre

Photo · Security team, operations centre

How it is built

Six things reviewers
always ask.

Identity

Your own tenant at [org].karos.cloud, set once and locked. SSO, passwordless or password, plus email OTP and an authenticator code.

Access control

A Capability × Role matrix is the source of truth. Owner ⊃ Super Admin ⊃ Admin ⊃ Member ⊃ Viewer, enforced identically in UI and API.

Data residency

Built and hosted in Canada by a Calgary team. Your data does not leave the region to be processed.

Auditability

Every create, edit, transfer and approval logged with actor, timestamp and portal. Agent actions are logged as the user who asked.

Agent behaviour

The agent inherits the requester's permissions, drafts rather than submits, and is write-blocked on certificates, objectives and hiring.

Cost control

AI credits capped per organisation and per employee per day, so an agent cannot generate unbounded spend.

Access model

The matrix, not a
marketing summary of it.

An abridged view of the org-scope permission matrix. The full capability list is shared under NDA during the review. Karos AI resolves through this same matrix.

CapabilityOwnerSuper AdminAdminMemberViewer
Complete org setup✓––––
Billing & subscription✓––––
Transfer ownership✓––––
Delete or close org✓––––
Manage system config✓✓–––
Manage AI credits✓✓–––
Invite & manage people✓✓✓––
Manage groups✓✓✓––
Publish announcements✓✓✓––
Create & edit portal records✓✓✓✓–
Use Karos AI✓✓✓✓–
Read permitted records✓✓✓✓✓
For the review

Questions we get
from security teams.

Do you train models on our data?

No. Your content answers your questions. It is not used to train shared models.

Which model do you use?

Model selection is engine-agnostic and confidential. Organisations see credits, never provider or raw cost.

Can we restrict which portals the agent reaches?

Yes. Restricting a portal for a role restricts it for the agent acting as that role.

What happens when someone leaves?

Access is revoked at role level, the record retained for audit. Ownership transfer is a separate owner-only action.

Do you support SSO?

Yes — SSO, passwordless and password, set at the organisation level.

Where do we send a questionnaire?

[email protected]. We complete standard questionnaires during cohort onboarding.

Request a demo

See it running on

your own data shapes.

Thirty minutes in a working environment configured for your sector. Live in under a day.