Trust without the theatre.
What we actually run today, who touches customer data, and how to report a vulnerability. No SOC 2 or ISO 27001 certificate yet. We say that out loud.
What we run.
Hosting
Application and marketing site on Vercel. Edge and serverless, TLS in transit.
Database
Postgres on Supabase with row-level security. Customer workspaces are isolated by tenant policy.
AI providers
OpenAI, Google Gemini and OpenRouter for conversation, scoring and scenario generation. Customer content is not used to train models.
Transactional mail via Resend.
Analytics
Plausible (cookieless) and Vercel Analytics. No advertising pixels.
Auth
Email and password for customer users. GitHub OAuth for TeamNumber-One operators.
What leaves the browser, and why.
Voice audio is transcribed to produce the next turn and the scored debrief. Transcripts, scores and uploaded playbooks stay in the customer workspace under the DPA. We do not sell personal data. Full detail lives in the privacy policy and the data processing agreement.
Read the privacy policy and the data processing agreement.
Who can see a workspace.
Customer admins invite their own users. Kulissa operators access a tenant only to fulfil a support request or a contractual obligation, and only with an audit trail. Production secrets live in Vault; agents and laptops do not share a standing database password.
How we build.
Dependency updates, typed contracts at the AI boundary, and schema validation on every model answer before it is stored or shown. Claims a model makes about the customer's own data are checked against the data we actually supplied. We do not publish a pen-test report we do not hold.
What we do not claim.
Kulissa does not hold SOC 2 or ISO 27001 certification today. Both are on the roadmap as we grow the customer base. Until then, the honest answer on a security questionnaire is the stack above, the DPA, and the subprocessor list.
Current subprocessors: /subprocessors.
Found something. Tell us.
Email hello@kulissa.com with the subject [Security]. Include steps to reproduce, the affected surface, and impact as you see it. Good-faith research that stays within the law is welcome. We acknowledge reports within two business days. Please give us a reasonable window before public disclosure.
Short answers for the questionnaire.
- Do you train models on customer data?
- No. Conversation turns, scores and scenario generation go to OpenAI, Google Gemini and OpenRouter only to produce that request's response. We require providers not to train on that content, and we do not train our own models on customer or Maya demo content.
- Where is data hosted?
- The application runs on Vercel. Postgres lives on Supabase. AI providers are US-based. Transfers out of Switzerland or the EEA use Standard Contractual Clauses as described in the DPA.
- Do you have SOC 2 or ISO 27001?
- Not yet. Both are planned. We publish the current stack, the DPA and the subprocessor list so buyers can review the facts we do hold.
- How do I report a vulnerability?
- Email hello@kulissa.com with subject [Security], or read /.well-known/security.txt. We acknowledge within two business days.
Security review for a pilot?
Send the questionnaire to hello@kulissa.com with [Security], or book a demo and bring procurement along.