Security

How the service is built, what is encrypted, and how to report something you have found.

Data In Transit And At Rest

Every media stream travels over DTLS-SRTP, and every API request requires TLS 1.2 or higher. A stored recording, transcript or avatar asset is encrypted at rest.

Credentials

A provider key is encrypted per organization and is never returned by the API after it is written. A tool credential is scoped per avatar, and a tool that has not been granted is never placed in the model context.

Access Control

An organization supports roles and usage caps. Every utterance, tool call and credential grant is recorded to an audit log an organization can export.

Reporting A Vulnerability

Send findings to security@kikasuite.com. We acknowledge a report within two business days and keep you updated until the issue is resolved. Please do not test against another organization's data.