Data In Transit And At Rest
Every media stream travels over DTLS-SRTP, and every API request requires TLS 1.2 or higher. A stored recording, transcript or avatar asset is encrypted at rest.Credentials
A provider key is encrypted per organization and is never returned by the API after it is written. A tool credential is scoped per avatar, and a tool that has not been granted is never placed in the model context.Access Control
An organization supports roles and usage caps. Every utterance, tool call and credential grant is recorded to an audit log an organization can export.Reporting A Vulnerability
Send findings to security@kikasuite.com. We acknowledge a report within two business days and keep you updated until the issue is resolved. Please do not test against another organization's data.