Trust and security
The answers a security review asks for first, written from what Kaloko does today. If something is missing, write to support@sinfin.cz.
SOC 2
Kaloko is not SOC 2 certified and has no SOC 2 report yet. We are preparing for a Type I audit: our controls are mapped to the criteria and the gaps are written down with a plan, but no auditor has been engaged. Until a report exists, we fill in security questionnaires and send the data processing agreement on request.
Where your data lives
Kaloko is built on Cloudflare. The application runs on Cloudflare Workers, the database is Cloudflare D1, and screenshots, recordings and other run files are in Cloudflare R2. Cloudflare picks the data centers; we have not pinned the data to one region.
The service is operated by Sinfin in the Czech Republic, and the terms follow Czech law. A run is deleted on the expiry date you set (30 days by default); accepted runs on Business and Enterprise stay while the plan lasts.
Encryption
- Every connection uses HTTPS. A request over plain HTTP is redirected.
- Cloudflare encrypts the database and the stored files at rest.
- Secrets Kaloko keeps for you are encrypted again with AES-GCM under keys only the service holds: Slack, Teams, Jira and Linear tokens, OIDC client secrets, SIEM tokens, passwords for hosted runs, SAML private keys and authenticator-app secrets.
- Sign-in links, sessions, API tokens, SCIM tokens and invitations are stored only as SHA-256 hashes.
- Uploaded files are served from a separate domain under short-lived signed links.
Who gets in
People sign in with an e-mail link or with Google, Microsoft or GitHub, and add a passkey or an authenticator app as a second step; from Business up an organization can require it. Enterprise adds company sign-in over SAML or OIDC (with encrypted assertions and single logout), SCIM provisioning, an IP allowlist and the audit log sent to your SIEM. Security-relevant actions are written to an audit log that admins filter and export from Business up.
Signed acceptance records
An accepted run (Business and up) comes with a signed acceptance record: who approved what and when, with a SHA-256 hash of every screenshot, signed with Ed25519. Anyone can check it against our public key or with the CLI:
Public key of the acceptance records: kaloko.app/.well-known/kaloko-signoff.json
kaloko signoff <run> --verify kaloko-signoff-<run>.pdfSubprocessors
Companies that process data so Kaloko can run. List last changed on 3 October 2026.
| Company | What for | What it receives |
|---|---|---|
| Cloudflare | Hosting, database, file storage, DNS, bot protection at sign-up, cookieless website analytics, browsers for hosted runs | Everything you upload and every request |
| Stripe | Payments and invoices | Billing contact, company and tax details; card details go to Stripe directly, never through Kaloko |
| Resend | E-mail delivery | The recipient's address and the e-mail itself |
| Sentry | Error reports | Error messages with addresses and URLs removed; no request bodies, cookies or headers |
| Anthropic | Hosted vision evaluation, only for criteria marked vision | A scaled screenshot or a crop of it, and the question |
| Typesafe | Hosted semantic evaluation, only when you use it | A reduced text outline of the page with e-mail addresses and tokens masked |
| Google Fonts | Fonts on our web pages | The visitor's IP address and browser details when a page loads its fonts |
Integrations you connect yourself (Slack, Microsoft Teams, Jira, Linear, GitHub, your identity provider, your SIEM) get what you choose to send them, under your own contract with them.
Report a vulnerability
Write to support@sinfin.cz with “Security” in the subject. Please give us time to fix the issue before you publish it. The same contact is in /.well-known/security.txt.
Documents on request
The data processing agreement, answers to your security questionnaire and a summary of our SOC 2 preparation. Ask for them →