Karelos processes workspace data to provide the service and keeps customer data separated from model training claims.
KarelOS security posture
Review how KarelOS reports data handling, subprocessors, prompt and secret protection, integration governance, and workflow separation of duties with status-aware claims.
Security controls
Certification, residency, retention, identity, and zero-retention claims stay in their real status until the owning control is live.
Customer workspace data is handled for service delivery and is not represented as foundation-model training data.
Prompt canary checks, tool-result redaction, and injection-guard evidence are tracked as PRD19 controls.
Governed integration calls use posture, scope, approval, consent, budget, and rate-limit checks before execution.
Workflow publish and gate controls preserve no-self-approval and dual-control evidence.
Security document requests route through the existing customer support path while DPA and BAA availability remain status-aware.
Request security documentsCertification and subprocessors
Public posture is shown as status text and supporting copy, not color alone.
Certification status
| Control | Current posture | Status |
|---|---|---|
| SOC 2 | SOC 2 evidence is tracked as status-aware security posture and is not claimed as complete until attestation is complete. | In progress |
| ISO 27001 | ISO 27001 readiness is shown as status-aware posture and is not claimed as complete until certification is complete. | In progress |
Subprocessors
| Area | Current posture | Status |
|---|---|---|
| Subprocessors | Current subprocessors and infrastructure providers are listed with status-aware availability. | In progress |
Security document access
Security document requests route through the existing customer support path while DPA and BAA availability remain status-aware.
Request security documents