Skip to main content
KalinkloOS

Enterprise & Security

Enterprise answers, before the questionnaire arrives.

One platform. Two operating systems. Explicit controlled seams — governed by reviewed access, least-privilege permissions, an auditable record of every action, and honest answers about what is live today and what is not.

Security posture

The controls, running in production.

Each item maps to a control in force today, not a promise. The full practice register — 6 of these expand into sixteen — lives on /security.

Reviewed access, private by default

Signing up creates a pending-approval account; an admin reviews before any dashboard data opens. There is no path that bypasses the gate. Reviewed-access codes can fast-track trusted workspaces.

Role-based access control (RBAC)

One identity opens role-scoped workspaces. Members, substitutes, librarians, personnel managers, artists, agents, presenters, and admins each see only the records their role can safely use. Entitlements gate sensitive actions (e.g. exports require CAN_EXPORT_REPORTS).

Audit log on every transition

Operational state changes — requests, holds, quotes, contracts, invoices, settlements, document opens, acknowledgements, and admin actions — write to the audit log with actor, timestamp, entity, and payload diff. SSO and SCIM identity transitions use the same audited, tenant-scoped boundary.

Multi-tenant isolation

Every protected endpoint runs an ownership check before responding. Cross-workspace detail probes collapse to 404 so an attacker cannot distinguish a real record from one they cannot access. List endpoints scope queries to the caller's workspace.

MFA on privileged surfaces

Admin dashboards require both a valid session and the admin MFA gate. Sign-in is passwordless by default (magic link). OIDC SSO is available only to an approved, configured enterprise tenant after real-IdP certification.

Rate limits + brute-force guards

Mutation endpoints carry per-actor rate limits. The public contact endpoint is limited per IP with a durable counter. Failed sign-in attempts are throttled and logged. CSP pins scripts to an allow-list, denies eval and framing; no advertising or cross-site tracking pixels load on the public site.

Enterprise identity

SSO and SCIM for approved, certified enterprise tenants.

The identity surfaces remain unavailable by default. An approved tenant must complete configuration and deployment-bound real-IdP certification before activation.

OIDC single sign-on — per-org, fail-closed
The per-organization path supports issuer, client ID, encrypted client secret, allowed email domains, PKCE, and fail-closed routing. It is available only to an approved tenant after deployment-bound proof with that tenant's real IdP.
SCIM 2.0 provisioning
The tenant-scoped SCIM Users endpoint uses timing-safe bearer-token checks and soft de-provisioning. It is available only to an approved tenant after deployment-bound lifecycle and isolation proof with its real IdP.
Approval and real-IdP proof are required
SSO and SCIM are controlled enterprise capabilities, not general availability features. Administrator configuration alone is insufficient: each tenant requires explicit approval and deployment-bound identity lifecycle certification before use.

Data & privacy

Your data, your control — in and out.

Export self-serve, delete on demand, and read the retention windows before you ask. The full retention table and processor list are on /privacy and /security.

You own your data
Your roster, relationships, and records are yours. We do not sell or share contact data, and we never use it for marketing outside Kalinklo.
Self-serve export
Export at any time from the reports center — 20+ tenant-scoped CSV exports across requests, bookings, quotes, contracts, invoices, settlements, collections, disputes, roster, and activity. Export requires the CAN_EXPORT_REPORTS entitlement and is scoped server-side.
Deletion on demand
Workspace owners can delete vault documents on demand; superseded uploads are preserved in the audit trail for integrity. Engagement business records carry legal retention obligations (below) and are handled accordingly.
Retention, by record class
Engagement records: life of the workspace + 7 years after closure (tax/legal). Vault documents: as long as the workspace exists, owner-deletable. Authentication events: 12 months. Health probes log no PII. The full table lives on /security.
DPA — template now, countersignature on request
A Data Processing Agreement template is downloadable right now (no request needed). For a countersigned copy for your organization, write to security@kalinklo.com. GDPR and HK PDPO posture is covered; US database region (us-east-1) today, EU residency planned; subprocessors published.
No advertising or cross-site tracking
The public site loads no advertising or cross-site tracking cookies. It does run cookieless, aggregate first-party analytics from our hosting provider (Vercel Analytics and Speed Insights) to measure page performance and usage; these set no cookies, do not identify you across sites, and are not shared with ad networks. Disclosed in the privacy notice.

Integrations

Honest status — live, provider hold, planned.

We do not list aspirational integrations as live. Calendar feeds are live and one-way; payments and e-signature are on provider hold; deeper provider calendar sync is planned. The complete table is on /integrations.

Calendar feeds (.ics)Live
Read-only, one-way feeds — subscribe in any calendar app or download a file. My Week via tokened URL; public profiles expose an availability feed. Not two-way sync.
Payments (Airwallex)Provider hold
Subscription/payment-provider path where configured. Engagement settlement remains manual until provider proof is approved. Payment collection stays out of public claims until an owner-approved charge + webhook proof pass.
Email (Resend)Provider hold
Transactional email path for magic-link sign-in, notifications, invites, and digests. Webhook signatures verify server-side. Live self-serve email is claimed only after domain, send, webhook, and bounce proof.
E-signature (Dropbox Sign / DocuSign)Provider hold
Contract signature path. Today contracts version, preview, download, manual-upload, and audit-track inside Kalinklo. Provider-backed signing stays out of public claims until proof passes.
Provider calendar syncPlanned
Deeper Google/Outlook provider sync for availability and confirmed engagements. Not shipped — today's read-only .ics feeds already work in Google Calendar and Outlook.
Error monitoring (Sentry)On request
Active only when SENTRY_DSN is configured. PII scrubbed before transmit.

AI safety

Drafts only. A human approves every commitment.

The same boundary is published on the AI policy on /security.

01

Drafts only — never an action

Where a workspace explicitly enables AI, it may summarize or draft internal text. It may not sign contracts, send external messages, issue invoices, process payments, publish materials, or change settlement state.

02

A human approves every commitment

No counterparty-facing message, contract, invoice, or settlement change moves without a person confirming the exact payload. The approval itself is audited — who clicked, when, on what.

03

Off by default, minimal context

AI is off entirely when no provider key is set. When on, prompts carry only the specific text being drafted — not your document library — and your data is not used to train models. Each run is logged (task, model, token counts, approval outcome).

Compliance status

Where we are on certification — honestly.

We do not yet hold SOC 2 or ISO 27001. We will not say otherwise. The controls those audits examine are live today and listed above. What follows is the certification path, stated as targets.

SOC 2 Type IIn preparation
Readiness assessment of point-in-time control design. We do not hold this certification today.
SOC 2 Type IIPlanned
A multi-month observation window evidencing controls over time — begins after Type I. The report most US institutions ask for. Not held today.
ISO 27001Planned
Stage 1 documentation review, then Stage 2 certification audit. The European procurement standard. Not held today.
GDPR + HK PDPOAvailable now
DPA template downloadable from the Trust Center; processor list published; US database region (us-east-1) today, EU residency planned.

The full roadmap with status notes is on /security.

Procurement FAQ

Straight answers before the questionnaire.

The general FAQ covers pricing, visibility, and settlement on /faq. These are the buyer, legal, and IT questions.

Are you SOC 2 or ISO 27001 certified?

Not yet, and we will not say otherwise. The controls those audits examine — audit logging, tenant isolation, gated documents, MFA, defined retention — are live today and documented on /security. SOC 2 Type I is in preparation; SOC 2 Type II and ISO 27001 are planned.

Do you support SSO and SCIM?

Only through a controlled enterprise rollout. Tenant-scoped, fail-closed OIDC SSO and SCIM require explicit tenant approval and deployment-bound real-IdP lifecycle certification before customer use; they are not generally available.

Can we get a Data Processing Agreement (DPA)?

Yes. The DPA template is downloadable right now — no request needed. For a countersigned copy for your organization, write to security@kalinklo.com.

Can we pay by invoice / purchase order?

Yes — invoice/PO with bank-transfer settlement is the standard billing path for controlled pilots and institutional buyers. We capture your PO reference, issue the invoice, and settlement is recorded manually against it with a full audit trail. Card payments are not required.

Can we export — and delete — our data?

Yes, self-service. The workspace owner can download the whole workspace as one JSON file (roster, productions, services, assignments, engagements, document manifest, audit-log slice) from Settings — step-up verified and audit-logged — plus 20+ tenant-scoped CSVs from the reports center. Owners can delete vault documents on demand; engagement business records follow the published legal-retention windows.

Can we take payments and e-sign contracts inside Kalinklo today?

Not as a public claim. Settlement remains manual until provider proof is approved, while contracts version/preview/upload/audit inside Kalinklo; provider-backed payment collection and e-signature stay on provider hold until owner-approved proof passes. The honest, current status for every integration is on /integrations.

How do we submit a security questionnaire?

Send it to security@kalinklo.com. Completed questionnaires come back with current control evidence; the same address handles DPA countersignatures and vulnerability reports, on the response timeline published on /security.

How is access granted — can anyone self-serve into our data?

No. Access is reviewed: signup creates a pending-approval account, and an admin approves before any dashboard data opens. Public pages never expose real workspace, member, artist, or engagement data.

Diligence, answered

Security review should not start from a sales deck.

Start with the trust packet and DPA above. For vendor questionnaires, DPA countersignature, or institution-specific review, write to the office.

Enterprise & Security | Kalinklo