Security & privacy
Your financials are the most sensitive files your business has
KAM is built around that assumption. Here's the current posture, stated plainly.

Encrypted everywhere
Files are encrypted in transit (TLS) and at rest. Uploads go directly to private storage through signed, expiring URLs — financial documents never sit in a public bucket, ever.
Tenant isolation by design
Every record is bound to your organization with database-level row security. Cross-tenant access paths are tested as part of our release checks.
Your data is not training data
AI providers are configured to prohibit training on customer data. Uploaded document text is treated as untrusted data, never as instructions — a deliberate defense against prompt-injection attacks hidden in documents.
No banking credentials
KAM never asks for bank usernames or passwords. You upload statements and exports; we never hold credentials that could move money.
Retention you control
Configurable retention with a verifiable deletion workflow. When you delete an entity or your account, the underlying files and derived data go with it.
Honest processing
If a file can't be parsed (a scanned PDF, an unsupported format), KAM says so and tells you what to upload instead. No silent failures, no pretend analysis.
Roadmap, stated honestly
KAM is in pre-launch. A SOC 2 Type II program is on the roadmap and will matter especially to firms managing client data; until an audit is complete we will not claim certifications we don't hold. Questions about our practices: security@teartech.com. Last reviewed: August 2, 2026.