Identity and access
Customer access is tied to the verified organisation and entitlement. Privileged cross-tenant support requires a separate owner session, fresh step-up verification and a recorded support reason.
Security and data handling
This page describes the product controls customers can rely on today and the boundaries that still require environment-specific validation. It does not claim a certification that has not been independently granted.
Operational controls
Customer access is tied to the verified organisation and entitlement. Privileged cross-tenant support requires a separate owner session, fresh step-up verification and a recorded support reason.
Organisation, target, provider and entitlement boundaries are checked server-side. A browser state or route alone cannot grant another tenant access.
The platform records evidence and operational metadata needed for the authorised assessment. Raw secrets are referenced through controlled storage and are not included in customer reports.
Evidence records preserve provenance, collection time, scope, confidence and integrity hashes so a conclusion can be traced to its source.
Security-relevant access and connector lifecycle actions are recorded in an audit trail, while service health and evidence freshness are monitored for accountable follow-up.
Retention follows the applicable product and legal terms. Authorised source revocation and deletion are validated as part of the connector lifecycle; a specific request is handled through KMayer support.
AI-assisted output remains evidence-bound and subject to validation. Public pages do not claim that KMayer enforces every customer AI agent, DLP policy or third-party model boundary.
Customer responsibilities
Questions before purchase
Ask KMayer to confirm supported sources, required permissions, expected freshness, retention, deletion handling, processing location and the evidence delivered for your approved scope.
Purchase-to-value path