Security & privacy
What protects your workspace, and what we have not built yet
Kharazm holds ordinary but sensitive material: who owns a program, what is behind, which risks are open, and what stakeholders were told. This page describes the controls enforced in code, where data is hosted, and the gaps we know about. It is written for a procurement reviewer, not only an engineer.
Why it is built this way
Boring controls, honestly described
Any team responsible for sensitive program data should be able to account for the tools it uses. The three ideas below are what we would want to defend in that conversation.
Enforced, not documented
Every control on this page is implemented in the application, and the ones that matter most — tenant isolation, role checks — are covered by automated tests that run before anything ships.
No third-party browser traffic
No analytics, trackers, external font or script host run in the browser. Server-side hosting, database and optional email providers are disclosed above rather than hidden behind that browser claim.
Gaps stated up front
No certification, no third-party pen test, no self-serve deletion yet. You should hear that from us at evaluation time, not from a security questionnaire three months in.
Keep reading
Related pages
Privacy policy
What we collect, why we collect it, how long we keep it, and how to ask for it back or ask us to delete it.
Read the privacy policyFeatures
Programs, tasks, milestones, timeline, RAID log, stakeholder updates and the audit log the controls above protect.
See what is in the productAccess and pricing
Compare Free, Standard and Premium rates, alongside the current limits of direct activation and manual commercial terms.
Compare plansQuestions your security review needs answered?
Send the questionnaire, the specific control, or the constraint you are working under. We will answer directly, including where the answer is "not yet".