Security and data.
How Karu Tech handles your system and your data.
How it works
Where it runs. Providers with SOC 2 data centers (an independent audit of security and availability): Cloudflare, Supabase, AWS, Google Cloud, or whatever your company already uses. The provider and region for your system are named in the proposal, before you sign.
Data residency. Region set by contract, depending on the provider and your operation.
In transit. Every connection is encrypted (TLS, the padlock in your browser): what leaves your computer reaches the system without anyone in between being able to read it.
At rest. Data stays encrypted when stored in the database as well: anyone reaching the disk without authorization reads nothing.
Backup and restore. Automatic backups by the platform itself; the step-by-step restore procedure is part of the documentation we include.
Access and isolation. Each client has its own system and its own database, separate from everyone else's. At Karu Tech, each person signs in with their own account, and who did what is logged. No data is shared between clients.
Roles. Karu Tech is the processor, handling the data on the client's behalf; the client is the controller, deciding what is done with it (terms from the LGPD, Brazil's data protection law). For clients outside Brazil, the roles and the applicable law are written into the contract.
End of contract. A final export of the data and the schema; deletion within a period set in the contract.
This site. No cookies, no trackers, and no form that stores data. The host keeps technical access logs. The contact funnel composes the message in your browser and sends nothing to a server.
A question about a specific point?
Write to us. We read everything and reply in writing.