Protected workspace access
Account and workspace access is checked before private conversations, connected context, or operating controls are shown.
Explore Kona
Chat for answers. Workspace for defensible work.
Trust center
Kona publishes what is verified, what is limited, and what remains planned. This page is a product-control statement—not a certification, audit report, or contractual security addendum.
Questions about trust or data use?
Review the public policies or contact the Kona team for a direct answer.
Contact supportAccount and workspace access is checked before private conversations, connected context, or operating controls are shown.
Connector credential storage is blocked unless the required AES-256-GCM encryption configuration is present.
Provider write operations remain disabled. Approval interfaces are control foundations, not a claim that Kona can modify a connected service.
Planning workflows keep sources, assumptions, owners, and review context close to the output they support.
Private workspace information appears only after account and access checks.
The Privacy Policy and Terms of Service are the public source of record for how Kona handles data and service use.
Current readiness
Last reviewed August 14, 2026. Deployment health can change independently of this product-control review.
Protected API paths use server-side session checks and resource-ownership checks for private conversations and workspace records.
Planning work can preserve source records, assumptions, formula lineage, verification state, and artifact versions for review.
Encrypted credential storage requires the deployment encryption key. Provider permissions and upstream controls still apply.
Item-level controls and chat exports exist, but a single self-service action does not yet cover every account data type and provider.
Run records and operational histories exist in defined workflows; they are not represented as a complete immutable enterprise audit log.
Enterprise SSO, SCIM, independently reviewed tenant isolation, and formal access recertification are not generally available.
Kona does not currently claim SOC 2 or ISO certification, a published penetration-test program, or a contractual uptime SLA.
Data principles
01
Use connected business context only for the workflows and workspace experiences a user chooses to run.
02
Separate public product information from private workspace state, credentials, diagnostics, and administrative settings.
03
Make it clear where a person should review evidence, approve an action, or provide missing business judgment.