Security
Your data stays yours. We score behavior, not store identity.
Karma3 extracts behavioral patterns from event streams and scores them. We do not build profiles from PII, we do not retain raw events longer than necessary, and the scoring model operates on derived features, not identifying fields.
Our Principles
Designed to minimize what we hold
These three principles govern how Karma3 handles every byte that passes through the platform.
Minimal Collection
We collect only the event metadata required to derive behavioral features. No full names, no payment card data, no government ID fields are ingested by the platform. The SDK is built to strip those fields at the source before transmission.
Encrypted in Transit
All data transmitted between your platform and Karma3 endpoints uses TLS 1.3 with certificate pinning on mobile SDKs. API keys are scoped per environment (sandbox vs. live). No plaintext traffic is accepted on any endpoint.
No PII in the Scoring Model
The ML scoring layer operates on derived behavioral features, not on raw event fields. User identifiers are hashed before feature extraction. Names, email addresses, and contact fields are never passed to the model and are not stored in the feature store.
Compliance
Built to align with major privacy frameworks
Karma3 is not a compliance tool, but the platform's data handling is designed to make your GDPR and CCPA obligations easier to meet, not harder.
GDPR Alignment
Data minimization is a first-class design constraint, not a checkbox. Behavioral features are derived and aggregated; the raw event stream is not retained beyond the active session window. EU data residency is available on Scale plans, keeping data within the EEA throughout ingestion and scoring. Deletion requests from your users propagate to Karma3 feature stores within 30 days through the platform API.
Our Data Processing Agreement (DPA) is available to all paying customers. Reach out through your account team or at [email protected] to request a signed copy.
CCPA Alignment
Karma3 does not sell behavioral data to third parties. The platform operates as a service provider under CCPA, processing data only on behalf of and under the instructions of your business. Consumer opt-out signals passed through your platform can be propagated to Karma3 via the deletion and suppression API to exclude those users from scoring entirely.
California residents whose data is processed by platforms using Karma3 can submit deletion or opt-out requests to those platforms directly. We provide platform customers with the API tooling required to fulfill those requests.
Infrastructure
What runs under the scoring layer
Access Controls
Production infrastructure access requires multi-factor authentication and is limited to engineering staff with a documented need. All access events are logged to an immutable audit trail. Third-party infrastructure vendors are evaluated on security posture before onboarding.
Incident Response
Karma3 maintains a written incident response policy with defined detection, containment, and notification timelines. Contractual breach notification commitments are included in Scale plan agreements. Security incidents affecting customer data are disclosed within 72 hours of confirmation.
Vulnerability Management
Dependency scanning and static analysis run on every code merge. Critical vulnerability patches follow a 24-hour remediation SLA in production. Responsible disclosure reports can be sent to [email protected].
Data Retention
Raw behavioral event payloads are retained for 30 days on Starter, 90 days on Growth, and custom on Scale. Derived feature vectors are retained for the duration of the subscription for scoring continuity. All retention windows are configurable to shorter periods on request.
Questions
Security questions deserve direct answers
If you are evaluating Karma3 and have specific questions about our data handling, encryption, or compliance posture, reach out. We will connect you with an engineer, not a brochure.