Public posture | Private pilots

Security and trust

How Kairnex protects your workspace and your evidence.

KairnexEvidence is designed to limit who can enter a workspace, keep customer records separated, protect stored evidence, and share only the information intended for a reviewer.

No hosted pilot is opened until its sign-in, customer separation, storage, encryption, export, and external smoke checks have passed for that environment.

Private access | Focused sharing

Core protections

Protect access, stored proof, and the final customer packet.

Security is applied across sign-in, customer separation, stored files, imported records, review history, and anything prepared for an outside reviewer.

Sign-in and roles

Workspace users sign in and receive only the permissions needed for their assigned work or review.

Customer separation

Organizations and their records are separated so one customer cannot access another customer's workspace data.

Protected evidence

Hosted setup requires encrypted evidence storage, managed secrets, controlled key rotation, and tested backup and export behavior.

Focused, verifiable sharing

Snapshots and exports retain integrity details while keeping unrelated workspace information out of the customer packet.

Source-tool boundary

Focused tools can send useful records, not passwords or raw secrets.

Each approved import keeps its source, owner, time, status, and verification details. Every source uses a separate approved delivery path.

Unsafe fields rejected Raw passwords, secrets, tokens, credentials, cookies, private keys, session material, and sensitive prompts are rejected.
Separate verification Each approved source receives its own verification key and limited delivery path.
Source history retained The source tool, package ID, version, timestamps, hashes, and verification result stay connected to the record.
One final review Source tools contribute focused records; KairnexEvidence keeps the review status, report, snapshot, and customer packet together.

What Kairnex does not claim

Organized evidence is not the same as an audit or certification.

Kairnex helps collect, review, and share evidence. Auditors, assessors, lawyers, insurers, customers, and other qualified decision-makers keep their own authority.

No claim that software alone creates or certifies compliance
No passwords, private keys, or sensitive evidence through public contact channels
No source import before customer approval and verification testing
No hosted pilot before the security and smoke-test gates pass

Report a security concern

Send only the minimum information needed to identify the issue.

Do not include customer evidence, credentials, private keys, tokens, or exploit data beyond what is necessary to identify the affected component and reproduce the issue safely.

Security contact

Include the affected page or component, what happened, the possible impact, and sanitized steps that reproduce it.

Email security contact