Security

Built around business-scoped data and permissioned AI

Here are the actual principles behind how Kalruck handles your business data and what AI Assistance are allowed to do — not marketing claims about certifications we don't hold.

Security principles

Business-scoped by design

Every document, conversation, and task in Kalruck is scoped to a specific business. Your Brain and AI Assistance only ever operate on your business's own data — not another tenant's.

Permissions on what a Assistant can do

AI Assistance only take actions you've explicitly allowed — like capturing a structured lead or request. They don't have open-ended access to take arbitrary actions on your behalf.

Deterministic backend state

The API is the single source of truth for your business data. The public marketing site and dashboard are interfaces to it — they don't hold or compute business state independently.

Grounded, non-inventive AI answers

AI Assistance are configured to answer only from your Brain and avoid inventing facts or pricing. When a question falls outside what your Brain covers, the Assistant is designed to escalate rather than guess.

Evidence and verification on real work

Tasks in AI Workspace can carry evidence — a file, document, or reference — and go through a verification step before being marked complete, so completed work is reviewable, not just claimed.

Auditable activity

Credit usage and task activity are tracked and visible in your dashboard, so you can see what was used, when, and by which Assistant or team member.

A note on certifications

We don't currently claim SOC 2, ISO 27001, HIPAA, or GDPR certification, or publish an uptime SLA. If a compliance certification matters for your business, please contact our sales team to discuss your requirements directly.

See how this looks in practice

Read how the platform is structured on the Architecture page.