Security
This page describes what Kalima can safely claim publicly today based on the current platform implementation.
Current controls we can state publicly
- Hosting: Google Cloud Run
- Secrets management: Google Secret Manager
- Primary datastore: MongoDB Atlas
- API authentication: JWT for authenticated platform access
- CAPTCHA: Cloudflare Turnstile where configured
- Two-factor authentication: TOTP with backup codes at the user level
- Audit logs: available for key actions on eligible plans
- Public SDK traffic isolation: dedicated SDK edge service for public endpoints
- SDK request controls: project-key validation plus layered IP, project, and global rate limits
Important wording boundaries
Kalima can say:
- audit logs are available for key actions on eligible plans
- SOC 2 is in progress
- public SDK traffic is served through a dedicated edge service with request controls
Kalima should not say:
- SOC 2 certified
- end-to-end encryption for all data
- full audit history for every plan and every event
Security contacts
Use info@kalima.digital for:
- security reports
- privacy or GDPR questions
- client requests that need security review
Client guidance
- Keep project keys scoped to the correct project and environment
- Use production and QA endpoints intentionally; do not mix them
- Handle
429responses with safe retry behavior - Contact Kalima if you need a documented review of plan-gated security features for procurement or onboarding
Support
Need security review material?
For security questionnaires, client onboarding reviews, or vulnerability reports, contact Kalima and include your company name, target environment, and requested turnaround.