Security

Control before convenience claims.

Kaldur is built as a multi-tenant platform. Security decisions belong on the server, sensitive actions need clear boundaries, and processing must remain understandable.

01

Tenant separation

Organisations and personal spaces are separated by the host being addressed. Sessions remain bound to that context.

02

Server-side policy

Permissions, model access and tool approvals are not left to the client alone.

03

Deliberate actions

Tools with external effects or increased risk can require explicit confirmation.

04

Controlled providers

External model and search services are reached through the Kaldur server and identified transparently in the privacy notice.

05

Content and operations

Product content remains in the product platform; administration and billing data are treated separately.

06

Deletion and retention

Accounts, content, logs and backups follow defined lifecycles rather than unlimited retention.

Transparency

Which data goes where.

Depending on the feature selected, content may be sent to Microsoft Azure AI, OpenAI, or selected models through OpenRouter. Web searches may use Brave Search. Details, legal bases and your rights are set out in the privacy notice.

Privacy notice →