Skip to main content

Securitybuiltin,claimskepthonest

Kairoo protects your career and learning data with a layered security model, a transparent compliance posture, and performance targets we measure ourselves against - no overstated badges, just the practices behind them.

  • TLS 1.3 + AES-256
  • Defense in depth
  • Data minimization
  • Continuous monitoring

Fast is a feature - and a target

A secure product still has to feel instant. These are figures we design and monitor against - targets, not guarantees.

<s<1.2sFirst Contentful Paint target
<ms<200msAPI response time target
256AES-bit encryption at rest
3Defense-in-depth layers

How we talk about compliance. We describe our posture as compliance-ready and in progress rather than overstating certifications - where a framework is fully reflected in how we operate today, we say so; where it's on our roadmap, we say that too.

A layered security model

Security is enforced at every layer - from the edge of the network, through the application, down to the data itself.

Layer 01 - Edge

Network security

Traffic is filtered, encrypted, and rate-shaped before it ever reaches the app.

Control coverage96%
  • Web application firewall with DDoS protection
  • SSL / TLS 1.3 encryption in transit
  • IP allow-listing for administrative access
Layer 02 - Runtime

Application security

Every request is authenticated, authorized, and scoped to least privilege.

Control coverage94%
  • OAuth 2.0 + JWT authentication
  • Role-based access control (RBAC)
  • API rate limiting and abuse protection
Layer 03 - Core

Data security

Your data is encrypted at rest, minimized, and isolated by design.

Control coverage98%
  • AES-256 encryption at rest
  • PII anonymization and data minimization
  • Secure key management (HSM-backed)

Every layer, control by control

Switch between the network, application, and data layers to see the concrete controls behind each one.

Hardened at the edge

Nothing reaches application code until it has been inspected, encrypted, and rate-shaped.

Web application firewall

Inline WAF with DDoS absorption and anomaly rules at the edge.

TLS 1.3 in transit

Modern ciphers only; HSTS and forward secrecy enforced.

Admin allow-listing

Privileged surfaces are reachable only from known IP ranges.

Rate shaping

Per-client throttling protects the platform from abusive bursts.

What happens to a request, end to end

From the moment data leaves your device to the moment we respond to an anomaly - every stage is accounted for.

  1. 01

    Encrypted in transit

    TLS 1.3 secures every byte from your device to our edge.

  2. 02

    Inspected & authorized

    WAF, auth, and RBAC validate the request before it runs.

  3. 03

    Stored & minimized

    AES-256 at rest, with PII reduced to what's truly needed.

  4. 04

    Monitored continuously

    APM, logs, and error tracking watch for anomalies in real time.

  5. 05

    Responded to fast

    Alerts route to on-call so regressions get fixed before they spread.

How we operate, day to day

The principles that shape every feature we ship.

Encryption everywhere

TLS 1.3 in transit and AES-256 at rest, so your data is protected on the wire and on disk.

Least-privilege access

Role-based access control and HSM-backed key management keep credentials and secrets tightly scoped.

Data minimization

We collect only what a feature needs and anonymize PII wherever the product allows.

Continuous monitoring

Application performance monitoring, metrics, log aggregation, and error tracking give us real-time visibility into the platform.

Where we stand on the frameworks

Each framework below shows what it covers and exactly where Kairoo sits today - stated plainly.

SOC 2

In progress

Security, availability & confidentiality controls

Targeting SOC 2 Type II. Controls are being implemented and documented ahead of a formal third-party audit.

GDPR

Aligned

EU/EEA personal data protection

Built to be GDPR-ready: data-subject access and deletion, lawful-basis handling, and EU data-processing practices.

HIPAA

In progress

Protected health information (where applicable)

HIPAA-ready architecture for healthcare use cases. A signed BAA and full safeguards are part of our enterprise roadmap.

ISO 27001

In progress

Information security management

Designing our information-security management system against ISO/IEC 27001 controls as we scale toward certification.

Working through a procurement or vendor-security review? Reach out and we'll share our current documentation and walk you through the controls behind each framework.

Request security docs

The thresholds we hold ourselves to

A secure product still has to feel instant. These are the thresholds we design and monitor against. They are targets, not guarantees.

Speed targets

  • First Contentful Paint (FCP)

    First content visible

    < 1.2s
  • Largest Contentful Paint (LCP)

    Main content loaded

    < 2.5s
  • Time to Interactive (TTI)

    Page fully responsive

    < 3.8s
  • API response time

    Typical request latency

    < 200ms
  • AI processing time

    Per AI-assisted action

    < 5s

Monitoring & observability

We watch these targets continuously so regressions surface fast and get fixed before they affect you.

  • Application performance monitoring (APM)
  • Metrics visualization & alerting
  • Centralized log aggregation & search
  • Real-time error tracking

Security questions, answered straight

No hedging, no overstated badges - here's exactly where we stand.

Straight answers, no overstated badges

We are intentionally precise here: Kairoo is built to be compliance-ready and our controls are mapped to these frameworks, but we do not claim active certifications we have not yet completed. SOC 2 Type II, ISO 27001, and full HIPAA safeguards (including a BAA) are in progress on our roadmap. GDPR practices are already part of how we handle personal data.

Security questions before you commit?

Tell us about your requirements and we'll walk you through our controls, documentation, and roadmap.