Browse the Help Centre

Security overview

Where the system runs

Karas runs on servers we operate ourselves in Vienna, not on a managed search or database service. The only component reachable from the internet is the web front door that terminates TLS; the application, the database, the search process and the cache are reachable only from inside that private network.

Encryption

All traffic to and from Karas is over HTTPS. Helpdesk credentials are encrypted before storage and can only be written by an operator using a command-line tool — there is no interface, for us or for you, that reads one back.

Credentials in logs

No credential is ever written to a log line or included in an error message. This is enforced by tests rather than by care, so it cannot regress unnoticed.

What reaches the assistant

Your documentation and the visitor's question. Karas has no connection to your orders, your customer records, your payment provider or your admin systems, and cannot be given one through the chat. There is no action it can take on a customer's account, because there is no mechanism for it to take one.

Redaction before data leaves us

Payment card numbers, card security codes, passwords and API tokens are stripped from a conversation transcript before it is sent to your helpdesk. See What a handoff ticket contains.

Tenant separation

Your documentation is searched with a filter fixed to your account, applied inside the search itself rather than by discarding results afterwards. The account is taken from your key and can never be set in a request body. The fallback search path enforces the same filter — a fallback that dropped it would quietly widen a search to everything, which is the exact failure mode this is written to prevent.

What we do not have

Being straightforward about the current state rather than implying more:

  • No SOC 2 or ISO 27001 certification.
  • No single sign-on for account access.
  • No customer-facing audit log.
  • No published uptime commitment. See Service reliability.

If your procurement process requires any of these, tell us early so we can be honest about timing rather than wasting your time.

Reporting a vulnerability

Email dimitar@usekaras.com with enough detail to reproduce it. We will confirm receipt, keep you informed, and will not pursue anyone who reports a genuine issue in good faith and does not access other customers' data.