Last updated: 19 June 2026
Karobaar holds your business and your clients' data, so security is foundational, not a feature. This page describes the controls in place today. We'll keep it current as the program matures.
Data is encrypted in transit (TLS) and at rest. Secrets and credentials (e.g. connected integrations) are stored encrypted, never in plaintext.
Your data is isolated per customer and is never visible to any otherKarobaar customer — we do not pool customers' data in a shared application. Higher tiers can run on a fully dedicated, single-tenant deployment.
We follow least-privilege access internally. Every consequential action in the product passes through an approval gate and is recorded in an append-only audit log, so there's a clear trail of what happened and who approved it.
Karobaar runs on established cloud infrastructure — Neon (managed, backed-up Postgres) and Vercel (application hosting and file storage) — with vetted sub-processors for payments, email, AI and integrations. The full named list is in our Privacy Policy.
Content sent to AI providers for processing is governed by agreements that prohibit training their general models on your data. AI output is always surfaced for your review before anything is sent.
Found a vulnerability? We want to hear from you. Email security@karobaar.ai and we'll respond promptly.