Security

Built for a buyer conversation you can trust

Kassie represents your company in front of real buyers. Security, customer isolation, controlled access, grounded knowledge, and honest failure behavior are part of how the product is built.

Current controls

What is implemented today

These are the controls and operating boundaries Kassie supports today.

Approved knowledge and honest failure

Kassie answers from customer-approved knowledge and captures unanswered questions as gaps instead of inventing an answer.

Customer and tenant isolation

Customer-facing data access is tenant-scoped, with Row Level Security and server-side customer checks protecting supported data paths.

Authentication and permissions

Kassie Workspace requires authenticated access, and content-changing actions are restricted to authorized customer roles.

Encryption and secret handling

Supported integration credentials are encrypted by the application with AES-256-GCM and authenticated context before storage.

Integration authorization

Integration connections require customer authorization and use provider permissions and server-only storage boundaries for supported capabilities.

Operational data boundaries

Internal model-usage and cost records are not exposed through customer-facing database roles.

Infrastructure

Kassie's current application uses Vercel for application hosting and Supabase for managed database and authentication services.

Current compliance posture

Kassie does not currently claim SOC 2 Type I, SOC 2 Type II, ISO 27001, HIPAA compliance, or another certification that has not been completed and documented.

Product boundary

Buyer question to approved answer

  1. 01Buyer starts a website conversation
  2. 02Kassie uses the customer's approved knowledge and rules
  3. 03Supported integrations coordinate the authorized next step
  4. 04The customer reviews conversation and pipeline context in Workspace

Current compliance posture

Clear about what has not been completed

Kassie does not currently claim SOC 2 Type I, SOC 2 Type II, ISO 27001, HIPAA compliance, or another certification that has not been completed and documented.

Kassie does not display certification badges or language that implies an audit has occurred when it has not.

Security review

For a current technical review, contact raphael@kassie.ai.

More qualified pipeline for revenue leaders

Kassie

Connecting to Kassie…