Encrypted at rest
AES-256 on every disk and backup.
Security
Most of our work runs on public record. The rest stays locked to your company, behind human review.
AES-256 on every disk and backup.
TLS on every connection.
Row-level security keeps each company apart.
Non-public files cannot be indexed or embedded.
Nothing reaches you unreviewed.
Grants, exports and edits leave a record.
Outreach staff need MFA and a grant per company.
Model API content is not used for training.
Public record only
Private perimeter
Separated by the database role model, not by policy.
Ask us
Answered from this page only. Please don't type anything confidential.
| Question | Answer |
|---|---|
| Every data hop | Browser to the Vercel-hosted application to private Supabase database and storage. Authorized agent tasks can send prompt content through Vercel AI Gateway to OpenAI; published-document embeddings go to Voyage AI. |
| Model providers and account tier | OpenAI through Vercel AI Gateway is the pinned generation path; its underlying commercial tier has not been established. Voyage AI embeds published documents. No AI provider is approved for outreach today. |
| Retention and training terms | OpenAI API content is not used for model training by default, but request-level zero-data-retention is not enabled and abuse-monitoring retention can be up to 30 days. Voyage AI opt-out and the Claude team-account settings remain unverified. |
| Non-public material | Uploads begin unverified or embargoed. Database constraints prevent embargoed documents from being chunked or embedded, and research and drafting roles are separate. The current model-generation path is not approved for material non-public information until retention controls are verified. |
| Krypton AI staff access | Client membership is company-scoped. Outreach requires multi-factor authentication, current attestations and an explicit company-and-audience grant. Verified operators manage access. |
| Audit trail | Grant and revocation, brief publication and viewing, claim copying, activity and correction, exports and provider versions create append-only audit evidence. The system does not claim that every read or administrative action is logged. |
| Tenant isolation | Clients share a Supabase project and are separated logically by company identifiers, row-level security, tenant-bound sessions and database constraints. Each client does not have a dedicated database, schema or encryption key. |
| Encryption at rest and in transit | Vercel states AES-256 encryption at rest and TLS 1.3 in transit. Supabase states AES-256 encryption for disks and backups and TLS 1.2 for network traffic. Krypton AI does not add application-layer or customer-managed encryption keys. |
| Retention and deletion | Core documents and audit records do not have a general time-based expiry, and a complete tenant purge has not been implemented or tested. Outreach evidence is append-only. Krypton AI does not claim deletion on request. |
| Subprocessors | The core path uses Vercel, Supabase, OpenAI and Voyage AI. Email, calendar and meeting workflows can additionally use Postmark, Google or Microsoft, Recall.ai and Resend. |
| Microsoft environment compatibility | Microsoft Outlook calendar connection and browser access are supported. Entra single sign-on, SharePoint or OneDrive content integration, Azure or virtual-network deployment, customer-managed keys and processing inside a customer's Microsoft tenant are not implemented. |
Krypton AI does not hold SOC 2 or ISO certification. Read the public-record services in the standing routines.