Skip to main content
Owner-approved · professional review pending

SECURITY / VERIFIED BOUNDARIES

Controls we can show. Gates we will not hide.

Kyntra does not claim a certification, penetration-test outcome or production control that the release evidence does not prove. This page separates implemented boundaries from open security gates.

Status. This is the current operative version of this document — an owner-approved company document that applies to your use of Kyntra today. It has not been reviewed by licensed counsel; professional legal review is planned, and this page will record that review when it completes. Material changes are announced as described in the Terms of Service.

LAST REVISED · 1 SEPTEMBER 2026

Verified product boundaries

  • Project scope is derived server-side for authenticated Code launch; public links do not carry workspace, tenant or project authority.
  • Onboarding resumes through an opaque transaction token kept out of URLs and OAuth state.
  • The backend enforces project and rolling-30-day build-credit allowances from the server-owned plan.
  • Public API health and plan endpoints support release verification without exposing provider credentials.

Browser-security status

This release candidate adds response security headers and must pass production browser tests. Browser bearer storage remains a High/FAIL item until the authentication owner replaces or formally accepts that design; this page does not describe it as a secure cookie session.

Open High/FAIL gates

  • CSP compatibility and enforcement across public, auth and signed-in surfaces.
  • Eliminate or formally remediate bearer material persisted in browser storage.
  • Dedicated preview-origin isolation and its cross-origin authorization contract.
  • Plugin registry authorization, consent, credential brokering and tenant-denial coverage.

Claims intentionally not made

  • No SOC 2, ISO 27001, HIPAA, PCI or other certification claim.
  • No claim that every data table has verified row-level security.
  • No published incident-response time or support SLA without an approved staffed operation.
  • No claim that a draft security page satisfies a customer questionnaire or contract schedule.