Scoped authorization
Organization, role, team, participant, and claim-level controls restrict data and actions to the people who need them.
Documents, claim conversations, and customer evidence need more than a perimeter. Kiso builds access, verification, and an audit trail into the work itself. We will sit with InfoSec and go through it.
A concise view of Kiso’s current product controls, written in the language security and operations teams evaluate.
| Control | What it means |
|---|---|
| Encryption in transit | Traffic to Kiso is encrypted. |
| Authentication | Accounts, scoped roles, secure links, optional OTP and step-up at higher-risk moments. |
| Audit | Delivery, access, signature, status, assignment, upload, and admin events stay with the work. |
| File handling | Short-lived upload links, malware scanning, original preservation, controlled access to media. |
| Tenancy | Organization A cannot read organization B’s claims or documents. |
| Retention / legal hold | Revocable access, transcript export, and legal hold support governed operations. |
Each control answers a simple question: who should be able to see or do this, and what evidence should remain afterward?
Organization, role, team, participant, and claim-level controls restrict data and actions to the people who need them.
Secure links, expiring access, consent steps, optional OTP, and step-up verification support higher-risk moments.
Delivery, access, signature, status, assignment, upload, and administrative events create an operational history.
Secure uploads, short-lived original links, malware scanning, document integrity checks, and separated derivatives reduce exposure.
Org A cannot read org B’s claims or documents. Tenant boundaries are part of every request path—not a slide in a pitch.
Legal hold, revocable access, transcript export, and configurable workflow records support governed operations.
We’ll walk InfoSec through controls in a 45-minute review: architecture, data flow, access, communications providers, and subprocessors under NDA.
Current controls, represented accurately. This page does not claim SOC 2, HIPAA, or another regulated-status designation unless it has been expressly documented for your agreement and deployment.