Skip to main content
KVL GrowthOS is now live — automate your first pipeline in 15 minutes.Get started
Enterprise Ready

Security & trust, documented honestly

GrowthOS is built on real, verifiable controls — role-based access enforced server-side, sensitive data encrypted at rest under independent keys, tamper-evident audit logs, and continuous health monitoring. Every claim on this page is backed by working code, not a marketing checklist, and we say so plainly where something isn't in place yet.

Contact Security Team
Encrypted Sensitive Data
Role-Based Access Control
Hash-Chained Audit Logs
Automated Nightly Backups
Cloud-Hosted
GDPR Data Controls
Enterprise Support
Architecture

How a request actually flows through this system

A real, current picture of the request path — deliberately described in generic infrastructure terms, not a diagram of aspirational infrastructure.

Browser

Your team and customers connect over HTTPS from any standard web browser.

Reverse Proxy (TLS Termination)

Incoming traffic is decrypted and routed by a reverse proxy in front of the application.

Application (Containerized)

The application runs in an isolated container, as a non-root user, with resource limits.

Database (PostgreSQL)

Application data is persisted in PostgreSQL and never exposed to the public internet.

Cache (Redis, Internal-Only)

Redis handles caching and rate limiting, reachable only from inside the internal network.

Encrypted Storage & Secrets

Sensitive data and credentials are encrypted at rest, each domain under its own independent key.

Automated Backups

A nightly job produces a checksummed, verified database backup automatically.

Health Monitoring

Database, cache, storage, and job-queue health are checked continuously and recorded over time.

Audit Logs

Sensitive actions are recorded in a tamper-evident, hash-chained audit trail.

Alerting

Critical failures trigger automated alerts to our operations channel the moment they're detected.

Principles

The principles behind how we build

Real engineering practices this codebase follows — expand a card for the detail behind the claim.

Compliance center

Where we stand, framework by framework

A real architectural-readiness snapshot — tap a framework for the full, unedited detail, including what it doesn't mean.

Certifications

Third-party audited certifications

Independent audits and partnerships, tracked separately from our own built-in security controls.

Third-party certifications

Coming soon

We don't hold any third-party audited certifications or cloud-provider partnerships yet. This is separate from our own security features — see the Security & Compliance section for the controls already built into the platform.

This isn't built yet — check back in a future release.

Encryption

How data is protected at rest and in transit

Every claim below is backed by working code in this platform.

AES-256-GCM Encryption

Sensitive data — agent memory, integration tokens, secrets, webhook signing keys, 2FA secrets — encrypted at rest, each under its own independent key.

TLS / HTTPS

Production traffic is served over HTTPS.

Password Hashing

Passwords are hashed with bcrypt/Argon2 — never stored in plain text, never reversible.

Secrets Management

A dedicated, encrypted secrets vault stores credentials — values are never selectable through the listing UI, only metadata.

Encrypted API Tokens

Integration OAuth tokens and API credentials are encrypted before being stored.

Access control

Who can do what, and how it's enforced

Every claim below is backed by working code in this platform.

Role-Based Access Control

Ten distinct roles with server-enforced, tenant-isolated permissions.

Two-Factor Authentication (TOTP)

Authenticator-app-based 2FA, with the secret encrypted at rest.

Session Security

Sessions can be revoked server-side at any time — a real 'log out everywhere,' not just clearing a cookie.

Hash-Chained Audit Logs

Sensitive actions are recorded in a tamper-evident, cryptographically chained audit trail.

API Authentication

API access uses bearer tokens that are hashed before storage — the raw key is never stored or retrievable again after creation.

Secrets Vault

Credentials are encrypted at rest in a dedicated vault, never exposed through the listing UI.

Infrastructure security

A hardened, isolated deployment — not just a claim

Every item below is backed by working infrastructure in this deployment — tap a card for detail.

Monitoring & incident response

Watched continuously, not checked occasionally

From detection to public disclosure — here's what actually happens when something breaks.

  1. 1

    Continuous Health Checks

    Database, cache, storage, and queue health are checked automatically and recorded over time.

  2. 2

    Automated Alerting

    Critical alerts are dispatched automatically to our operations channel the moment they're detected.

  3. 3

    Incident Tracking

    Real incidents are logged, tracked to resolution, and reviewed — not handled ad hoc.

  4. 4

    Transparent Status

    Real historical uptime is publicly visible on our status page — not a marketing claim.

Real historical uptime, publicly visible

Live health checks and incident history — not a marketing claim.

View real-time system status
Data privacy

Your data, under your control

Real, working privacy controls built into the product — not just a policy document.

Self-Service Data Export

Download a complete export of your own data as JSON, on demand — no request ticket or waiting period required.

Protected Account Deletion

Deleting or anonymizing your account is a genuinely destructive-action-protected flow — you must type a confirmation phrase and re-enter your password before anything is removed.

First-Party Cookie Consent

Analytics cookies are opt-in and off by default. We only set them after you explicitly consent, and you can withdraw that consent at any time.

Manage your data

Export or delete your data directly from your account settings.

Privacy requests

Have a question about how we handle your data? Reach our support team directly.

GDPR & DPA

GDPR-aligned data rights, for real

Consent, export, and deletion are backed by working code — not just a policy statement.

We record real, timestamped consent for the cookies and processing you agree to, and we back the rights the GDPR grants you with working features: a genuine self-service data export and an account deletion/anonymization flow that requires typing a confirmation phrase and re-entering your password before anything is removed.

Export my data

Download a full copy of your data as JSON from your account.

Delete my data

Delete or anonymize your account, protected by a confirmation phrase and password re-check.

Data Processing Agreement (DPA)
Available on Request

Documentation request

Need a copy of our Data Processing Agreement or other GDPR documentation? Reach out and we'll send it over.

Data residency

Where your data lives

A straightforward, honest statement about our current hosting footprint.

Single-region, cloud-hosted deployment today.

All application data is currently hosted in a single cloud region. Customer-selectable region and multi-region failover are on our roadmap but not available yet — we won't claim otherwise until they're real.

Coming soon

Resources we're still preparing

These aren't ready yet — we'd rather tell you honestly than fake it.

Security Whitepaper

Coming soon

A downloadable architecture and controls overview is in progress.

This isn't built yet — check back in a future release.

Penetration Testing

Coming soon

No third-party penetration test has been conducted yet — real results will be published here once one has.

This isn't built yet — check back in a future release.

Responsible Disclosure Program

Coming soon

A formal vulnerability-disclosure policy and security contact are in progress.

This isn't built yet — check back in a future release.

Documentation

Enterprise security documents

Some documents are available to download right now; others are available on request while we finish preparing them.

Privacy PolicyAvailable
Terms of ServiceAvailable
Cookie PolicyAvailable
Data Processing Agreement (DPA)Available on RequestContact us
Security WhitepaperAvailable on RequestContact us
Service Level Agreement (SLA)Available on RequestContact us
Business Continuity & Disaster Recovery SummaryAvailable on RequestContact us
Access Request FormAvailable on RequestContact us

Put your growth engine on autopilot

Start qualifying, engaging, and converting pipeline with AI agents today. No credit card required, and your first workflow can be live in under fifteen minutes.