Security & Trust

Neutral. Isolated. Auditable.

Your evaluation data reveals your research priorities. We built Kamapathy so that trusting us with it is a defensible decision — contractually, architecturally, and operationally.

security@kamapathy.app — we answer security questionnaires and share our current compliance status.

Neutrality

No lab owns us. No lab sees you.

In a market where data vendors keep consolidating around the biggest labs, independence is the first control.

Independent by design

Kamapathy is not owned by, invested in by, or affiliated with any AI lab. We never have a competing stake in the models our clients are building.

Your data trains nothing of ours

Client prompts, model outputs, rubrics, and deliverables are used solely to complete your project. We do not train models on them, benchmark with them, or reuse them in any form.

No cross-client exposure

Projects are isolated per client. Experts on your project cannot see any other client's work, and nothing from your engagement is visible to anyone outside it.

Deletion on request

At the end of an engagement we return your deliverables and, on request, delete project data from our systems — confirmed in writing.

Data protection

Controls that are live today

Not aspirations — this is how the production platform is built right now.

Encryption in transit and at rest

TLS on every connection — our domain is HSTS-preloaded, so unencrypted requests are impossible — and encryption at rest across our database and file storage providers.

Role-based access, tenant isolation

Five distinct roles with server-side enforcement on every endpoint. Clients see only their own workspace; experts see only projects they are qualified onto.

Project-scoped expert access

Experts must be individually screened and qualified onto each project before its tasks become visible to them. Access is revocable per project at any time.

Private file storage, expiring links

Uploaded files live in private buckets. Every download passes a server-side permission check and uses a signed URL that expires within minutes.

Hardened authentication

Passwords hashed with scrypt at OWASP parameters, opaque session tokens hashed at rest, HttpOnly secure cookies, brute-force lockout, and per-route rate limiting.

Complete audit trail

Every claim, submission, review decision, approval, and payout is recorded with actor, role, IP, and request ID — an immutable record of who touched what, and when.

Confidentiality

Paper that protects you, not just us

Every layer of the engagement is contractually bound before any sensitive detail changes hands.

Mutual NDA before any brief

We sign a mutual NDA before you tell us anything about your research priorities. Your interest in a capability area is itself confidential.

Every expert under contract

All experts sign confidentiality and IP-assignment agreements before touching any work. Deliverables and everything produced on-platform belong to you.

Confidentiality tiers per project

Projects carry a confidentiality level that governs how they are described to experts, what metadata is visible, and how deliverables are handled.

Quality assurance

Quality you can inspect, not just claim

Trust in the data comes from the process that produced it — and from being able to see that process working.

Three-stage vetting

Identity verification, credential and background review, then per-project screening assessments. Experts qualify onto each project individually — approval to the platform is not approval to your data.

100% human review before delivery

Every submission passes rubric-based review with per-item scores before it reaches your deliverable. Weak work is rejected or sent back for revision, never passed through.

Live quality metrics

Your client dashboard shows approval rates, average review scores, throughput, and qualified-expert counts in real time — the same numbers our operations team is accountable to.

Per-item provenance

Each delivered datum carries who produced it, who reviewed it, its score, and its full history. You can audit any item back to its origin.

Compliance

Certification roadmap

We are transparent about where we are: strong controls today, formal attestations in progress. No badge inflation.

  1. Now

    Security-first architecture

    The controls above are live in production today — RBAC, tenant isolation, audit logging, encrypted storage, and contractual confidentiality on every engagement.

  2. Next

    SOC 2 Type I → Type II

    SOC 2 is on our near-term roadmap: continuous-monitoring tooling first, then a Type I report, then the Type II observation period. Ask us for current status.

  3. Planned

    ISO 27001

    ISO 27001 certification follows SOC 2 as we grow our formal information-security management system.

GDPR- and DPDP-aligned data handling. Data processing agreement available on request.

Put us through your security review

Send your questionnaire, request our DPA, or start with a mutual NDA. We would rather earn trust early than ask for it later.