Built to be trusted with the work that matters.
Kirality runs the busywork of regulated, real-world businesses — clinics, firms, practices, shops. That only works if your data is safe and every move is accountable. Here's exactly how we protect it, in plain terms.
Encryption at rest
Secrets and credentials — API keys, connector tokens, config secrets, PHI fields — are encrypted at rest with per-tenant derived keys (AES-256-GCM). Business records are isolated by database-enforced Row-Level Security on every tenant table and encrypted at the infrastructure layer.
Per-tenant keys
Every workspace gets its own key, derived (HKDF) from a platform master secret held in our deployment platform’s encrypted secret store. One tenant’s key cannot decrypt another’s data — isolation is cryptographic, not just logical.
Database-level isolation
Row-Level Security enforces tenant_isolation on every tenant table inside Postgres itself — isolation the database enforces, not just application code. Verified continuously by an automated RLS check that gates every build.
Glass-box audit ledger
AI-proposed and approved actions are recorded in an append-only, tamper-evident audit trail you can read — who did what, when. The AI proves its moves.
HIPAA-aligned retention
Health data is retained for the required window and hard-destroyed on schedule. Offboard and your data is purged on the clock, not forgotten in a backup.
You own your data
Export everything at any time, or delete it. No lock-in, no hostage data. Your business, your records.
We measure our own impact — honestly.
Most AI tools claim their AI works. Almost nobody measures it honestly, because honest measurement makes the numbers smaller. We'd rather show you a small true number than a big fake one — so measurement is built into the product, not bolted on for a pitch.
We start the clock at send, not draft
An outcome is only counted once the action actually reaches your customer — never on a draft the AI wrote and nobody sent. No credit for work that didn't happen.
We count each result once
Fail-closed attribution: a $50,000 invoice the AI chases across five reminders is credited once, never five times. Duplicates can't inflate the scoreboard.
We show the denominator
For the actions we take, we report what share we can even observe — and admit the rest. A success rate always comes with "of the N outcomes we could actually measure."
We only learn from what you consent to
The improvement corpus captures your AI-drafted-vs-approved edits only after you opt in — executed actions only, fully exportable, and deleted on request.
Healthcare & BAA
For healthcare workspaces, a Business Associate Agreement is available on request as part of managed onboarding — we complete it with you before any PHI enters the platform. Our delivery team operates only through the AI with patient information masked at the human layer, access is least-privilege and fully audited, and PHI is encrypted at rest with a per-tenant key. Ask us for the BAA and current subprocessor list.
Talk to us about compliance →