Privacy & security

Security & trust

What we do today to protect your business and your customers' data — only measures that are actually in place.

How your data is protected

  • HTTPS everywhere

    Every page, the app and the API are served over HTTPS only, with HSTS (Strict-Transport-Security for one year, including subdomains), so browsers do not fall back to an unencrypted connection.

  • Traffic through Cloudflare

    All traffic to kautharai.com passes through Cloudflare's network, which helps absorb attacks and keeps our server's address hidden.

  • Each business in its own space

    Every record belongs to one business account, and every request the system handles is limited to that account: a business sees only its own data.

  • Permissions per team member

    The account owner decides what each team member can see and do, screen by screen.

  • Activity log and trash

    Every change is recorded with who made it and when. Deleted items go to a trash bin, where the owner can restore them or delete them permanently.

  • Hashed passwords

    Passwords are stored only as bcrypt hashes, never in readable form. Phone numbers are verified with a one-time SMS code, and session cookies are HttpOnly and sent over HTTPS only.

  • Encrypted connection keys

    Keys and passwords you give us to connect other services — your own AI provider key, your support mailbox password, your store API keys — are encrypted at rest with AES-256-GCM and are never shown back in full.

  • Nightly backups

    The database and uploaded files are backed up every night. Each backup is kept for 14 days and then deleted automatically.

  • AI on our own servers by default

    By default the AI runs on servers we operate, so your files and your customers' conversations are not sent to an outside AI company. Only if a business connects its own account with an AI provider (OpenAI, Anthropic, Google Gemini or a compatible service) are the messages needed for each reply sent to that provider, under the business's own account.

  • Card payments on the provider's page

    Subscription payments are made on our payment provider's secure page; card numbers never reach our servers.

  • Notification tokens

    The mobile app's notification token is used only to deliver notifications to that device, and it is deleted when you sign out.

  • Account deletion

    An owner can delete the business account from the app or the website. After a 14-day grace period (to cancel a mistake), the account and all its data and files are permanently erased; backups that still contain them expire within the next 14 days.

  • Access by our team

    Our platform administrators can open a business's account to provide support or keep the service running, and every such access is recorded in that business's activity log.

Report a security issue

If you believe you have found a vulnerability in Kauthar, email us the details and the steps to reproduce it. Please do not access or change other people's data while testing, and give us reasonable time to fix the issue before you disclose it. We read every report and reply as soon as we can.

Machine-readable contact: security.txt

If something goes wrong

If a security incident affects personal data, we will inform the affected businesses without undue delay, with what we know, the likely impact and the steps we are taking.

Let Kauthar answer for you, starting today

Sign up with your phone number, upload your files and share the link with your customers. Kauthar handles the rest, around the clock.

14-day free trialNo credit cardLive in minutes