Security and data handling

Authorised scope, evidence traceability and accountable access.

This page describes the product controls customers can rely on today and the boundaries that still require environment-specific validation. It does not claim a certification that has not been independently granted.

Operational controls

What is protected, and how the boundary is enforced.

Identity and access

Customer access is tied to the verified organisation and entitlement. Privileged cross-tenant support requires a separate owner session, fresh step-up verification and a recorded support reason.

Tenant separation

Organisation, target, provider and entitlement boundaries are checked server-side. A browser state or route alone cannot grant another tenant access.

Data minimisation

The platform records evidence and operational metadata needed for the authorised assessment. Raw secrets are referenced through controlled storage and are not included in customer reports.

Evidence integrity

Evidence records preserve provenance, collection time, scope, confidence and integrity hashes so a conclusion can be traced to its source.

Operational assurance

Security-relevant access and connector lifecycle actions are recorded in an audit trail, while service health and evidence freshness are monitored for accountable follow-up.

Retention and deletion

Retention follows the applicable product and legal terms. Authorised source revocation and deletion are validated as part of the connector lifecycle; a specific request is handled through KMayer support.

AI-assisted analysis

AI-assisted output remains evidence-bound and subject to validation. Public pages do not claim that KMayer enforces every customer AI agent, DLP policy or third-party model boundary.

Customer responsibilities

Authorise only assets and sources you control.

  • Confirm ownership or explicit permission for every assessed target.
  • Approve the exact tenant, account, repository, project or export boundary.
  • Use least-privilege access and revoke it when no longer required.
  • Review remediation in the customer environment before operational change.

Questions before purchase

Request a precise answer for your environment.

Ask KMayer to confirm supported sources, required permissions, expected freshness, retention, deletion handling, processing location and the evidence delivered for your approved scope.

Read the Privacy Policy

Read the Tool Use Policy

Purchase-to-value path

Know the scope before an assessment starts.

  1. ReviewInspect capability, security and integration boundaries.
  2. RequestSubmit the organisation, authorised target and provisional asset quantities without payment or assessment.
  3. VerifyConfirm the business recipient, authorised assets and tenant boundary.
  4. ApproveReview the provisional capacity, billing frequency and scope before approving PayPal.
  5. ReceiveA verified webhook activates server-side entitlement; assessment follows, then private outputs.
Start an exposure assessment
KMayer - IT Service Provider
Privacy Policy

Our website is committed to protecting your privacy. We collect and process data to enhance your experience, such as recognizing you when you return and understanding how you interact with our content. Your information is used responsibly to ensure that our services remain valuable, secure, and tailored to your needs. For a detailed explanation of how we handle and protect your data, please refer to our Privacy Policy