Security

Trust is part of
the retrieval pipeline.

Kivo is designed for least privilege, explicit tenant boundaries, and privacy-preserving operations from upload through deletion.

01

Tenant IDs required at every repository boundary

Implemented as a centralized, testable platform control—not a UI convention.

02

Private R2 objects with short-lived upload grants

Implemented as a centralized, testable platform control—not a UI convention.

03

Collection authorization before retrieval and generation

Implemented as a centralized, testable platform control—not a UI convention.

04

AES-GCM encryption for workspace-owned model keys

Implemented as a centralized, testable platform control—not a UI convention.

05

Hashed API keys and invitation tokens

Implemented as a centralized, testable platform control—not a UI convention.

06

CSP, strict cookies, CSRF and origin validation

Implemented as a centralized, testable platform control—not a UI convention.

07

Auditable lifecycle jobs and complete scheduled purging

Implemented as a centralized, testable platform control—not a UI convention.

08

Document text treated as untrusted prompt data

Implemented as a centralized, testable platform control—not a UI convention.