LEGAL & TRUST
Security and Service Reliability Statement
KRAVIA's standard is appropriate, risk-based protection and dependable service operated with reasonable professional care. This Statement does not certify a system, promise absolute security or create an uptime SLA that has not been separately agreed.
1
Scope and truthful assurance
Security measures depend on the service, data sensitivity, deployment and actual architecture. Public statements and customer assurance documents must identify the relevant scope and distinguish implemented controls from intended improvements. A planned audit, provider certification or marketing phrase is not a KRAVIA certification.
The detailed implementation record is maintained separately and shared only to the extent appropriate for confidentiality and security. Public transparency does not require publishing secrets, exploitation paths or another customer's records.
2
Access and confidentiality
Access to personal and customer information is limited to authorized people who need it for defined duties. Appropriate permissions, authentication, confidentiality obligations and access review support that restriction. Privileged and sensitive access requires stronger protection than ordinary browsing.
Private content is not routinely opened for general product improvement. Necessary support or investigation access must be narrowly scoped and appropriately recorded. Departure or role changes require timely reassessment of access.
3
Data and application safeguards
Risk-based controls include appropriate protection of data in transit and at rest, credential and secret handling, tenant and authorization boundaries, input validation, dependency maintenance, monitoring and secure configuration. Specific implementations must be verified before they are described as present features.
Passwords, where used, require appropriate one-way password protection rather than being recoverable for staff convenience. Encryption does not by itself prevent misuse by an authorized account. Access control, key management and operational practices remain important.
4
Customer responsibilities
Customers protect their credentials, secure devices, configure authorized users appropriately and report suspected compromise promptly. Organizations must apply suitable account administration and permissions to their own users. These duties complement rather than replace KRAVIA's responsibility for the platform it controls.
Connected third-party systems require their own appropriate safeguards. A customer-controlled integration does not grant blanket permission for a third party to receive all account data.
5
Testing, monitoring and change management
Services should be developed, tested, maintained and improved with reasonable professional care. Material changes are assessed for privacy, security, reliability and relevant user impact. Monitoring is proportionate to detecting errors, abuse and service health, not an excuse for unrelated behavioural profiling.
High-risk features receive appropriate privacy and AI review before production use. Vendors are reviewed according to the data and service they handle. Material weaknesses must be tracked and addressed according to risk rather than hidden behind a broad disclaimer.
6
Backups, continuity and recovery
Critical services require appropriate backup, restoration and continuity procedures with testing proportionate to their importance. Actual backup intervals, retention and recovery objectives are recorded for each product. A general backup statement is not a guarantee of zero data loss.
Specific uptime, restoration or support metrics are contractual only when included in an applicable SLA or order. Planned maintenance and significant incidents are communicated where appropriate, and affected functions are restored with reasonable urgency. The Product Sunset Policy addresses permanent discontinuation separately.
7
Incidents and notification
We investigate suspected incidents, contain harm, preserve necessary evidence, assess affected information and remediate weaknesses. Notices to customers, individuals, regulators and other authorities follow their respective legal and contractual triggers and deadlines. No single “72-hour” statement describes all global obligations.
Where a significant incident creates meaningful user risk, appropriate accurate information and protective steps may be communicated even beyond a minimum notification duty, when safe and lawful. Notification is not deferred solely because every investigative detail is unknown.
8
Reporting and assurance
Send suspected account compromise or other security reports to security@kraviaprivatelimited.com. Follow the Vulnerability Disclosure Policy for research. Do not include passwords or unnecessarily expose other people's information. Normal service problems may be reported to product support or support@kraviaprivatelimited.com.
Business customers may request proportionate assurance through an appropriate confidential process. Available reports must be accurately described. No ISO, SOC 2, HIPAA, PCI DSS or similar assertion is made by publishing this Statement alone.