# Security (summary)

- TLS everywhere; HSTS
- Encryption at rest for primary stores; MFA secrets AES-256-GCM
- API keys: Argon2id hashes only
- Webhooks: HMAC-SHA256 signatures
- Training on customer content: off by default
- Hard-fail on model errors (credits refunded)

Report: security@kranth.com  
Policy: https://kranth.ai/vulnerability-disclosure  
HTML: https://kranth.ai/security
