10//Security
What is in place, and what is not.
A plain list for a public beta. Kageform holds no customer accounts and keeps no notes on its servers, which keeps the surface small. It has no security certification (no SOC 2, ISO 27001 or similar) and is not for confidential, regulated or personal data. Last reviewed 2026-10-10.
01//Data kept
No accounts, no database of notes, no cookies and no analytics. Workspace notes live in page memory and disappear on reload. See Privacy.02//Data sent
Only when you press Ask AI coach after acknowledging, or press Ask in the example demo: your question, topic and the selected notices go to our server and then to the model provider named in Privacy. Local Find in browser sends nothing.03//Secrets
The model API key is a sensitive server-side environment variable on the hosting platform. It is never in client code, and a build-time check scans source and public files for credentials before release.04//Input limits
Requests are validated on the server: at most 8 notices, 500 characters per notice, 4,000 in total and 300 for the question. Model calls have short timeouts and output caps.05//Model output
Notices are treated as untrusted data, not instructions. Answers must cite notice IDs that exist in your request, otherwise the page falls back to written excerpts. This reduces, but does not remove, wrong answers.06//Transport and hosting
The site is served over HTTPS on Vercel. Hosting providers keep their own standard request logs. Email runs on Zoho Mail with SPF and DKIM configured.07//Dependencies
Dependencies are pinned in a lockfile and updated when advisories apply; the TanStack Start release was bumped on 2026-10-08 for a published advisory. There is no automated audit or penetration test yet.08//Not in place yet
No certifications, no independent audit, no role-based access, no single sign-on, no data-processing agreement, and no uptime or incident-response commitment. These are roadmap items that matter once real customer data is in scope.
Report a vulnerability: email founder@kageform.dev with steps to reproduce. Please do not access other people's data or disrupt the service. Good-faith reports get a reply and credit if you want it. There is no bug bounty. Machine-readable contact: security.txt.
← Back to the overview