New feature: AI Job Search! Try it now

Trust center

Security at Kairo

A conservative overview of safeguards visible in the product and how to report a security concern.

Last updated:

Our approach

Kairo is designed to separate public experiences from authenticated product data and to limit data operations to the signed-in user. Security is an ongoing practice, not a guarantee, and no internet service eliminates all risk.

Safeguards evidenced in the product

  • Authentication is handled through an identity provider, and protected product routes require an authenticated user.
  • Document and session operations are scoped by user identifiers, including ownership checks before document deletion.
  • API inputs use schema validation, and document uploads have file-type, file-size, text-length, and PDF expansion limits.
  • Administrative routes perform separate authorization checks based on configured administrator identities.
  • Sensitive configuration is loaded from environment variables rather than embedded in public page code.

Your role

  • Protect your sign-in method and sign out of shared devices.
  • Submit only information you are authorized to use and avoid unnecessary sensitive data.
  • Keep your device, browser, and Kairo desktop software updated.
  • Contact us promptly if you notice unexpected account activity or a suspected vulnerability.

Report a vulnerability

Email support@slabix.com with the subject “Security report.” Include the affected URL or feature, reproducible steps, and impact. Do not include secrets in the initial message.

Please avoid accessing other users’ data, disrupting service, using social engineering, or publicly disclosing a suspected issue before we have had a reasonable opportunity to investigate. We will review good-faith reports, but this page does not establish a paid bounty program or authorize activity that would otherwise be unlawful.

Assurance and vendor information

This page does not claim a security certification, penetration-test schedule, encryption configuration, data-residency commitment, or guaranteed response time. The available repository does not establish those details or a complete current list of service providers.

For a current security questionnaire, service-provider information, retention details, or contractual security requirements, contact support@slabix.com.