Security & data
How the beta protects your work, and its limits
What we do to protect your account and your plans, where your data lives, and what you should know before you trust the beta with important work. For the legal detail, see the privacy notice.
Access
No other KitAxis user can open your workspaces.
- The beta is invite-only, and every account needs a verified email address.
- Your access is checked on every request. If access is removed, it stops with the next request.
- Your workspaces are private to your account. Any other KitAxis user who tries to open them gets “not found”.
- Approving or revoking a sign-off requires your password again.
- Requests are rate-limited per person, per workspace and per network address.
- Sign-in is email and password. Two-factor authentication and single sign-on are not available yet.
Records you can rely on
History is kept, not rewritten.
- Plan revisions, evidence and audit records cannot be changed or deleted through KitAxis: database rules refuse it.
- Important actions, such as invites, access changes, plan changes and approvals, are written to an append-only audit log.
- Other exceptions are set out in the privacy notice (account deletion) and the beta terms (beta data resets).
- The records are not cryptographically sealed, so someone with administrator access to the server could still change them.
In transit and in the browser
Encrypted connections and a locked-down browser policy.
- Traffic is encrypted in transit (HTTPS only, with HSTS).
- A strict Content Security Policy limits what the pages can load. This website runs no scripts at all.
- The web app loads no third-party scripts except Google’s Firebase sign-in library.
Backups
Encrypted, off-site and restore-tested.
- The database is backed up every 6 hours. Backups are encrypted, and copies are kept off the server.
- Backups are restore-tested.
- Backups are kept for 14 days on the server and 30 days off-site, then removed.
- If the server fails, changes made since the last backup, up to about 6 hours, could be lost.
Where your data lives
The providers that run the beta.
- Oracle Cloud Infrastructure hosts the KitAxis server and database in the United States (San Jose region).
- Google Firebase Authentication handles accounts, passwords, and verification and password-reset emails. Your password goes from your browser straight to Google; the KitAxis server never receives or stores it.
- Cloudflare provides DNS, the network edge, the secure tunnel to our server, email routing for our support address, and storage for encrypted backup copies.
- Microsoft OneDrive (ProductSeal’s own account) stores encrypted backup copies, copied there each day from ProductSeal’s own computer. The decryption key is not stored in OneDrive.
- You cannot choose where your data is stored.
Your content
Used only to run the beta for you.
- KitAxis makes no AI model calls with your content.
- KitAxis does not use your content to train AI models, and never sells it. If you connect an AI assistant, what it reads is handled under its provider’s terms.
- You own what you put in.
Limits to know
What the beta does not offer yet.
- The beta runs on a single server with no high availability, and there is no uptime commitment.
- The live database is not encrypted beyond the cloud provider’s disk. Only backups are encrypted by us.
- ProductSeal, which runs the service, has administrator access to the server and can technically read or change your stored plans and evidence. There is no end-to-end encryption.
- KitAxis has not had an independent security audit and holds no compliance certification.
Report a problem
If you think you have found a security issue, email support@kitaxis.com with the details. Please don’t test against other people’s accounts or data.
If a breach affects your data, we will tell you as the law requires.