Your company's data, kept apart and in your control.
kanês holds the records a company runs on, and lets AI work on them. These are the controls that keep that safe, each one enforced in code or in the database, not only in the interface.
An action outside kanês, from request to result
- You ask
- kanês prepares it
- Sealed against change
- You confirm
- It runs as you
- Recorded
Where your data lives
Each company's records are kept apart by the database itself, not only by the interface.
Held in the EU
The database, sign-in and file storage run on Supabase in Frankfurt (eu-central-1).
Isolated per company
Row-level security is on for every table. A person reads and changes only what their membership and role in that company allow, and a record can never be moved to another company.
Encrypted on your device
The copy kept for offline use is encrypted with AES-GCM under a key made on that device, separately for each person and company.
Yours to take
An owner can download a full backup file of the workspace at any time, and a large deletion keeps a restorable version for 30 days.
Accounts and permissions
Access is decided per company and per person, and checked on the server for every change.
Roles and permissions
Owner, Admin, Manager, Employee and Viewer, plus custom roles and per-person grants. Deleting clients, deciding approvals and editing the company each need their own permission.
Two-factor sign-in
Every account can turn on two-factor sign-in with an authenticator app.
Breached passwords refused
New and reset passwords are checked against known breaches (Have I Been Pwned, by k-anonymity, so the password never leaves kanês).
An audit log
Changes to members, roles, AI connections, integrations, agents, approvals and exports are recorded with who made them.
AI and agent security
The model proposes; it never holds a permission. Authorization stays in code and in the database.
Your own AI key, encrypted
Each company's OpenAI or Anthropic key is encrypted with AES-256-GCM, bound to that company, and never shown again beyond its last four characters.
Agents act as the person
Every tool runs with the session of the person who asked, never with elevated access. Prompt text cannot raise a permission.
Outside actions wait for a yes
A calendar event, a GitHub issue or a company tool that writes elsewhere is prepared, sealed against change (HMAC) and run only after its author confirms it.
Voice consent from your words
In kanês Voice, a confirmation is read from your own transcribed words by code, never decided by the model.
Records are data, not instructions
Context sent to the model is marked as data, and an outside tool's answer is never fed back to the model as instructions.
No training on your data
kanês does not train models on your data. Requests go to the provider your company chose, under your company's own account and its terms.
Connections to other services
Each connection asks for the least it needs and is used only for the person who made it.
Least access
Google Drive is read only; Google Calendar can add events; the GitHub App reads and opens issues and never merges or pushes.
Sealed tokens
Refresh tokens are encrypted with the server's secret and bound to the company and the person who connected.
Safe outbound calls
Calls to a company's own MCP servers use HTTPS only and refuse private or internal addresses, checked again at connection time on every request.
How kanês is built and run
Security checks run on every change, not once a year.
Automated checks
Every change runs type checks, tests that include the database's security rules, a dependency audit and secret scanning.
Hardened web layer
Strict transport security, a content security policy, and no framing of kanês by other sites.
An incident plan
A written incident response plan covers detection, containment, notification and review.
Service providers
The services kanês relies on to run, and the ones your company may choose to connect under its own account.
- SupabaseDatabase, sign-in and file storage, in the EU (Frankfurt)
- RenderRuns the kanês web application
- CloudflareNetwork edge and DNS in front of withkanes.com
- StripeBilling for kanês plans and add-ons
- ResendSends kanês's emails, such as invitations
Chosen and connected by your company, under its own account: OpenAI, Anthropic (Claude), Google (Drive, Calendar), GitHub, The company's own MCP servers. See Integrations for what each one can read and change.
What we do not claim
kanês does not hold SOC 2, ISO 27001, HIPAA or PCI certification today, and no page of this site says otherwise. If your company needs a security questionnaire answered or a data processing agreement, contact us. To report a vulnerability, write to hello@withkanes.com.
Questions about security
Where does kanês store my data?
In the EU (Frankfurt), on Supabase. Each company's records are isolated in the database with row-level security on every table.
Does kanês train AI models on my data?
No. Requests go to the AI provider your company connected (OpenAI or Anthropic), under your company's own account and that provider's terms, with only the context a request needs.
Is kanês SOC 2 or ISO 27001 certified?
No. kanês does not hold SOC 2, ISO 27001 or similar certifications today, and does not claim to. This page lists the controls it does have.
Can an AI agent in kanês do something I am not allowed to do?
No. Every tool runs with the session of the person who asked, so the database applies that person's role. The model only proposes; it never holds a permission.
Start with the list
you already have.
Import a spreadsheet. It gets researched, scored and ordered before you open it.