Security & Trust
Neutral. Isolated. Auditable.
Your evaluation data reveals your research priorities. We built Kamapathy so that trusting us with it is a defensible decision — contractually, architecturally, and operationally.
security@kamapathy.app — we answer security questionnaires and share our current compliance status.
Neutrality
No lab owns us. No lab sees you.
In a market where data vendors keep consolidating around the biggest labs, independence is the first control.
Independent by design
Kamapathy is not owned by, invested in by, or affiliated with any AI lab. We never have a competing stake in the models our clients are building.
Your data trains nothing of ours
Client prompts, model outputs, rubrics, and deliverables are used solely to complete your project. We do not train models on them, benchmark with them, or reuse them in any form.
No cross-client exposure
Projects are isolated per client. Experts on your project cannot see any other client's work, and nothing from your engagement is visible to anyone outside it.
Deletion on request
At the end of an engagement we return your deliverables and, on request, delete project data from our systems — confirmed in writing.
Data protection
Controls that are live today
Not aspirations — this is how the production platform is built right now.
Encryption in transit and at rest
TLS on every connection — our domain is HSTS-preloaded, so unencrypted requests are impossible — and encryption at rest across our database and file storage providers.
Role-based access, tenant isolation
Five distinct roles with server-side enforcement on every endpoint. Clients see only their own workspace; experts see only projects they are qualified onto.
Project-scoped expert access
Experts must be individually screened and qualified onto each project before its tasks become visible to them. Access is revocable per project at any time.
Private file storage, expiring links
Uploaded files live in private buckets. Every download passes a server-side permission check and uses a signed URL that expires within minutes.
Hardened authentication
Passwords hashed with scrypt at OWASP parameters, opaque session tokens hashed at rest, HttpOnly secure cookies, brute-force lockout, and per-route rate limiting.
Complete audit trail
Every claim, submission, review decision, approval, and payout is recorded with actor, role, IP, and request ID — an immutable record of who touched what, and when.
Confidentiality
Paper that protects you, not just us
Every layer of the engagement is contractually bound before any sensitive detail changes hands.
Mutual NDA before any brief
We sign a mutual NDA before you tell us anything about your research priorities. Your interest in a capability area is itself confidential.
Every expert under contract
All experts sign confidentiality and IP-assignment agreements before touching any work. Deliverables and everything produced on-platform belong to you.
Confidentiality tiers per project
Projects carry a confidentiality level that governs how they are described to experts, what metadata is visible, and how deliverables are handled.
Quality assurance
Quality you can inspect, not just claim
Trust in the data comes from the process that produced it — and from being able to see that process working.
Three-stage vetting
Identity verification, credential and background review, then per-project screening assessments. Experts qualify onto each project individually — approval to the platform is not approval to your data.
100% human review before delivery
Every submission passes rubric-based review with per-item scores before it reaches your deliverable. Weak work is rejected or sent back for revision, never passed through.
Live quality metrics
Your client dashboard shows approval rates, average review scores, throughput, and qualified-expert counts in real time — the same numbers our operations team is accountable to.
Per-item provenance
Each delivered datum carries who produced it, who reviewed it, its score, and its full history. You can audit any item back to its origin.
Compliance
Certification roadmap
We are transparent about where we are: strong controls today, formal attestations in progress. No badge inflation.
- Now
Security-first architecture
The controls above are live in production today — RBAC, tenant isolation, audit logging, encrypted storage, and contractual confidentiality on every engagement.
- Next
SOC 2 Type I → Type II
SOC 2 is on our near-term roadmap: continuous-monitoring tooling first, then a Type I report, then the Type II observation period. Ask us for current status.
- Planned
ISO 27001
ISO 27001 certification follows SOC 2 as we grow our formal information-security management system.
GDPR- and DPDP-aligned data handling. Data processing agreement available on request.
Put us through your security review
Send your questionnaire, request our DPA, or start with a mutual NDA. We would rather earn trust early than ask for it later.
