Troi
These policies are drafts pending legal review and may change before launch.

Security Overview

DRAFT — pending review. Effective date: 2026-07-09 · Version: Draft 1.0 · Last updated: 2026-07-09. Operated by Kanah LLC (Wyoming, USA) for the Troi service. Referenced by the Data Processing Addendum (Art 32 measures) and the Privacy Policy.

In short: how we protect your data. This summarizes our technical and organizational measures. It is a plain-language overview, not a warranty; see the Terms for the legal disclaimers.


Hosting & infrastructure

  • Troi runs on Microsoft Azure. Data is hosted in the United States at launch; an EU-region option is planned. International transfers rely on Standard Contractual Clauses and the EU-US Data Privacy Framework (see the Privacy Policy and Sub-processor List).
  • Traffic is encrypted in transit with TLS.

Encryption at rest

  • Stored secrets and credentials (e.g., connected-service tokens) are encrypted with AES-256-GCM.
  • Sensitive identity fields — such as identity-document numbers (SSN/passport) and insurance policy numbers — are encrypted at rest with the same authenticated encryption.
  • Vault entries are encrypted.

Access control & tenant isolation

  • Access to your data requires authentication; every request is checked against workspace membership at a central authorization layer (default-deny), so one workspace cannot read another's data.
  • AI agents are denied access by default to sensitive Life data categories (health, cycle, journal, finance, identity documents) and can only read a category if you explicitly grant it.
  • Administrative access to production is limited and logged. [[FOUNDER: confirm internal access-control + least-privilege process]]

Application security

  • Security response headers (content-type-sniffing protection, framing protection, HSTS in production).
  • Uploaded files are served with protections that prevent a disguised file from executing as script in your browser.
  • Outbound fetches of user-supplied URLs pass a server-side safety check to prevent them reaching internal systems.
  • Rate limiting and abuse protections on sensitive endpoints (e.g., login).

The Troi Runner

  • The optional desktop Runner executes jobs your own account sends it, on your own machine. Its download is gated by an enrollment token, and its local state file is stored with owner-only permissions. See the Runner EULA.

AI providers

  • We use AI providers on a zero-retention / no-training tier — they do not train their models on your data, and retention is minimized. See the AI Transparency Disclosure.

Data retention & deletion

  • Data is retained per the schedule in the Privacy Policy and deleted on request (self-service account deletion, 30-day grace, then hard delete; backups purged within ~35 days).

Reporting a vulnerability

  • If you believe you've found a security issue, contact info@kanah.app. Please don't publicly disclose until we've had a reasonable chance to fix it.

Incident response

  • We maintain an incident-response process and will notify affected users and, where required, regulators without undue delay (and within 72 hours to a supervisory authority where GDPR Art 33 applies). [[FOUNDER: finalize breach-notification runbook with counsel]]

This overview describes our practices as of the effective date and evolves as the product does. It is provided for transparency and does not create warranties beyond those in the Terms of Service.