Trust & Security

Built to be trusted with the work that matters.

Kirality runs the busywork of regulated, real-world businesses — clinics, firms, practices, shops. That only works if your data is safe and every move is accountable. Here's exactly how we protect it, in plain terms.

Encryption at rest

Secrets and credentials — API keys, connector tokens, config secrets, PHI fields — are encrypted at rest with per-tenant derived keys (AES-256-GCM). Business records are isolated by database-enforced Row-Level Security on every tenant table and encrypted at the infrastructure layer.

Per-tenant keys

Every workspace gets its own key, derived (HKDF) from a platform master secret held in our deployment platform’s encrypted secret store. One tenant’s key cannot decrypt another’s data — isolation is cryptographic, not just logical.

Database-level isolation

Row-Level Security enforces tenant_isolation on every tenant table inside Postgres itself — isolation the database enforces, not just application code. Verified continuously by an automated RLS check that gates every build.

Glass-box audit ledger

AI-proposed and approved actions are recorded in an append-only, tamper-evident audit trail you can read — who did what, when. The AI proves its moves.

HIPAA-aligned retention

Health data is retained for the required window and hard-destroyed on schedule. Offboard and your data is purged on the clock, not forgotten in a backup.

You own your data

Export everything at any time, or delete it. No lock-in, no hostage data. Your business, your records.

How we hold ourselves accountable

We measure our own impact — honestly.

Most AI tools claim their AI works. Almost nobody measures it honestly, because honest measurement makes the numbers smaller. We'd rather show you a small true number than a big fake one — so measurement is built into the product, not bolted on for a pitch.

We start the clock at send, not draft

An outcome is only counted once the action actually reaches your customer — never on a draft the AI wrote and nobody sent. No credit for work that didn't happen.

We count each result once

Fail-closed attribution: a $50,000 invoice the AI chases across five reminders is credited once, never five times. Duplicates can't inflate the scoreboard.

We show the denominator

For the actions we take, we report what share we can even observe — and admit the rest. A success rate always comes with "of the N outcomes we could actually measure."

We only learn from what you consent to

The improvement corpus captures your AI-drafted-vs-approved edits only after you opt in — executed actions only, fully exportable, and deleted on request.

Healthcare & BAA

For healthcare workspaces, a Business Associate Agreement is available on request as part of managed onboarding — we complete it with you before any PHI enters the platform. Our delivery team operates only through the AI with patient information masked at the human layer, access is least-privilege and fully audited, and PHI is encrypted at rest with a per-tenant key. Ask us for the BAA and current subprocessor list.

Talk to us about compliance →