Kalokoby

Home

Trust and security

The answers a security review asks for first, written from what Kaloko does today. If something is missing, write to support@sinfin.cz.

SOC 2

Kaloko is not SOC 2 certified and has no SOC 2 report yet. We are preparing for a Type I audit: our controls are mapped to the criteria and the gaps are written down with a plan, but no auditor has been engaged. Until a report exists, we fill in security questionnaires and send the data processing agreement on request.

Where your data lives

Kaloko is built on Cloudflare. The application runs on Cloudflare Workers, the database is Cloudflare D1, and screenshots, recordings and other run files are in Cloudflare R2. Cloudflare picks the data centers; we have not pinned the data to one region.

The service is operated by Sinfin in the Czech Republic, and the terms follow Czech law. A run is deleted on the expiry date you set (30 days by default); accepted runs on Business and Enterprise stay while the plan lasts.

Encryption

Who gets in

People sign in with an e-mail link or with Google, Microsoft or GitHub, and add a passkey or an authenticator app as a second step; from Business up an organization can require it. Enterprise adds company sign-in over SAML or OIDC (with encrypted assertions and single logout), SCIM provisioning, an IP allowlist and the audit log sent to your SIEM. Security-relevant actions are written to an audit log that admins filter and export from Business up.

Signed acceptance records

An accepted run (Business and up) comes with a signed acceptance record: who approved what and when, with a SHA-256 hash of every screenshot, signed with Ed25519. Anyone can check it against our public key or with the CLI:

Public key of the acceptance records: kaloko.app/.well-known/kaloko-signoff.json

kaloko signoff <run> --verify kaloko-signoff-<run>.pdf

Subprocessors

Companies that process data so Kaloko can run. List last changed on 3 October 2026.

Subprocessors
CompanyWhat forWhat it receives
CloudflareHosting, database, file storage, DNS, bot protection at sign-up, cookieless website analytics, browsers for hosted runsEverything you upload and every request
StripePayments and invoicesBilling contact, company and tax details; card details go to Stripe directly, never through Kaloko
ResendE-mail deliveryThe recipient's address and the e-mail itself
SentryError reportsError messages with addresses and URLs removed; no request bodies, cookies or headers
AnthropicHosted vision evaluation, only for criteria marked visionA scaled screenshot or a crop of it, and the question
TypesafeHosted semantic evaluation, only when you use itA reduced text outline of the page with e-mail addresses and tokens masked
Google FontsFonts on our web pagesThe visitor's IP address and browser details when a page loads its fonts

Integrations you connect yourself (Slack, Microsoft Teams, Jira, Linear, GitHub, your identity provider, your SIEM) get what you choose to send them, under your own contract with them.

Report a vulnerability

Write to support@sinfin.cz with “Security” in the subject. Please give us time to fix the issue before you publish it. The same contact is in /.well-known/security.txt.

Documents on request

The data processing agreement, answers to your security questionnaire and a summary of our SOC 2 preparation. Ask for them →