Security

Trust without the theatre.

What we actually run today, who touches customer data, and how to report a vulnerability. No SOC 2 or ISO 27001 certificate yet. We say that out loud.

Stack

What we run.

Hosting

Application and marketing site on Vercel. Edge and serverless, TLS in transit.

Database

Postgres on Supabase with row-level security. Customer workspaces are isolated by tenant policy.

AI providers

OpenAI, Google Gemini and OpenRouter for conversation, scoring and scenario generation. Customer content is not used to train models.

Email

Transactional mail via Resend.

Analytics

Plausible (cookieless) and Vercel Analytics. No advertising pixels.

Auth

Email and password for customer users. GitHub OAuth for TeamNumber-One operators.

Data

What leaves the browser, and why.

Voice audio is transcribed to produce the next turn and the scored debrief. Transcripts, scores and uploaded playbooks stay in the customer workspace under the DPA. We do not sell personal data. Full detail lives in the privacy policy and the data processing agreement.

Read the privacy policy and the data processing agreement.

Access

Who can see a workspace.

Customer admins invite their own users. Kulissa operators access a tenant only to fulfil a support request or a contractual obligation, and only with an audit trail. Production secrets live in Vault; agents and laptops do not share a standing database password.

Application

How we build.

Dependency updates, typed contracts at the AI boundary, and schema validation on every model answer before it is stored or shown. Claims a model makes about the customer's own data are checked against the data we actually supplied. We do not publish a pen-test report we do not hold.

Certifications

What we do not claim.

Kulissa does not hold SOC 2 or ISO 27001 certification today. Both are on the roadmap as we grow the customer base. Until then, the honest answer on a security questionnaire is the stack above, the DPA, and the subprocessor list.

Current subprocessors: /subprocessors.

Responsible disclosure

Found something. Tell us.

Email hello@kulissa.com with the subject [Security]. Include steps to reproduce, the affected surface, and impact as you see it. Good-faith research that stays within the law is welcome. We acknowledge reports within two business days. Please give us a reasonable window before public disclosure.

FAQ

Short answers for the questionnaire.

Do you train models on customer data?
No. Conversation turns, scores and scenario generation go to OpenAI, Google Gemini and OpenRouter only to produce that request's response. We require providers not to train on that content, and we do not train our own models on customer or Maya demo content.
Where is data hosted?
The application runs on Vercel. Postgres lives on Supabase. AI providers are US-based. Transfers out of Switzerland or the EEA use Standard Contractual Clauses as described in the DPA.
Do you have SOC 2 or ISO 27001?
Not yet. Both are planned. We publish the current stack, the DPA and the subprocessor list so buyers can review the facts we do hold.
How do I report a vulnerability?
Email hello@kulissa.com with subject [Security], or read /.well-known/security.txt. We acknowledge within two business days.

Security review for a pilot?

Send the questionnaire to hello@kulissa.com with [Security], or book a demo and bring procurement along.