Trust center

Clear boundaries for business-critical AI work.

Kona publishes what is verified, what is limited, and what remains planned. This page is a product-control statement—not a certification, audit report, or contractual security addendum.

Questions about trust or data use?

Review the public policies or contact the Kona team for a direct answer.

Contact support

Protected workspace access

Account and workspace access is checked before private conversations, connected context, or operating controls are shown.

Protected connection flows

Connector credential storage is blocked unless the required AES-256-GCM encryption configuration is present.

Human review for consequential work

Provider write operations remain disabled. Approval interfaces are control foundations, not a claim that Kona can modify a connected service.

Visible evidence and assumptions

Planning workflows keep sources, assumptions, owners, and review context close to the output they support.

Workspace controls stay private

Private workspace information appears only after account and access checks.

Clear public commitments

The Privacy Policy and Terms of Service are the public source of record for how Kona handles data and service use.

Current readiness

Security claims with their boundaries attached.

Last reviewed August 14, 2026. Deployment health can change independently of this product-control review.

Private account resources

Protected API paths use server-side session checks and resource-ownership checks for private conversations and workspace records.

Verified

Planning evidence history

Planning work can preserve source records, assumptions, formula lineage, verification state, and artifact versions for review.

Verified

Connector credential protection

Encrypted credential storage requires the deployment encryption key. Provider permissions and upstream controls still apply.

Limited

Data export and deletion

Item-level controls and chat exports exist, but a single self-service action does not yet cover every account data type and provider.

Limited

Workspace audit history

Run records and operational histories exist in defined workflows; they are not represented as a complete immutable enterprise audit log.

Limited

Organization identity controls

Enterprise SSO, SCIM, independently reviewed tenant isolation, and formal access recertification are not generally available.

Planned

Independent assurance and SLA

Kona does not currently claim SOC 2 or ISO certification, a published penetration-test program, or a contractual uptime SLA.

Planned

Data principles

Practical rules for every workflow.

01

Collect with purpose

Use connected business context only for the workflows and workspace experiences a user chooses to run.

02

Keep boundaries visible

Separate public product information from private workspace state, credentials, diagnostics, and administrative settings.

03

Keep people accountable

Make it clear where a person should review evidence, approve an action, or provide missing business judgment.