Security

Draft — pending review · Last updated: July 2026

Authentication

Accounts use Supabase authentication with passwordless magic-link sign-in. Server endpoints verify the Supabase session token (JWT) on every request and derive your identity from that verified token — never from a user id supplied by the browser.

Access control & data isolation

User data (watchlists, conversations, saved analyses, entitlements, usage counters) is protected by PostgreSQL Row-Level Security so a row is readable only by its owner. Founder/co-founder roles unlock product features and quota exemptions only; they do not grant access to any other user's private records.

Secrets handling

Provider API keys, the database service-role key, and internal secrets are server-only environment variables. They are never shipped to the browser and never appear in client bundles. Public client configuration (Supabase anon key, Firebase web config, Razorpay key id) is public by design and protected by server-side rules.

Transport & browser hardening

Traffic is served over HTTPS with HSTS. Responses set X-Content-Type-Options, Referrer-Policy, Permissions-Policy and anti-clickjacking headers, plus a Content-Security-Policy (currently in report-only mode while it is tuned before enforcement).

Cost & abuse protection

Expensive AI endpoints require authentication, enforce input and output limits, provider timeouts, a global spend cap, duplicate-request protection, and per-user product quotas. Additional durable per-user rate limits are being rolled out. These protections apply to all accounts, including founder/co-founder.

Logging

Server logs are redacted to avoid recording authorization headers, cookies, tokens, keys, or full private message content. Error responses returned to the browser are generic and do not expose stack traces, SQL, or internal details.

Data deletion

You can request deletion of your account and associated data by emailing support@kairo.app from your account email. We will remove your account record and associated user-owned data. Some records may be retained where required for legal, security, or fraud-prevention purposes.

Reporting a vulnerability

If you believe you have found a security issue, please email security@kairo.app with details and steps to reproduce. Please do not publicly disclose the issue until we have had a reasonable opportunity to investigate and remediate. Do not access or modify other users' data while testing.

What we do not claim

No online service can guarantee absolute security. KAIRO makes no claim of any security certification, encryption certification, or regulatory approval. This page describes current practices and may change as the product evolves.

Privacy →Terms →Disclaimer →Back to home