Skip to content
Trust and security

Your participants' data, handled like it's ours.

Every organization on Karsenics runs on its own isolated service. Nobody sees another organization's people, money, or plans, and card numbers never touch us. This page says exactly what we do, what we've had checked, and what's still in progress. Where a document backs a claim, you can ask for it.

Last reviewed September 2026 · reviewed quarterly
What's true today

Four things you can count on before you read anything else.

These aren't goals. They're how the platform is built and run right now.

Your organization is on its own island.

Each organization gets its own service, its own storage, and its own database, hosted in the United States and encrypted at rest and in transit. There's no shared database and no switch that could show one organization another's data, because the data isn't in the same place.

Your organizationown service · own database
Another orgown service · own database
Another orgown service · own database

Named people, no passwords to leak.

Your team signs in with a one-time link to their email. There's no password to reuse or steal. Your Primary Administrator decides who can see money, send messages, or change registrations, and can switch anyone off in one click.

Payments go to Stripe, never through us.

When a participant pays, they're handed to Stripe's own checkout page. Stripe is certified at the highest level of the card industry's security standard. Card numbers never reach Karsenics; we receive a payment confirmation. We're completing the card industry's self-assessment for this kind of setup, and we'll sign it every year.

Backed up every day. Restored on purpose, not just hoped for.

Your data is snapshotted daily and kept encrypted. On July 21, 2026 we restored a backup end to end and checked it, because a backup nobody has tested is a hope. From Q4 2026 that test is scheduled every quarter, with each result recorded.

Independent assurance

Where we stand, without the badge wall.

Some of these we do ourselves and document. Some need an outside auditor. Most are in progress today, and each one says so with a date.

PCI DSSCard payment security
In progress, target Q4 2026
Stripe handles every card. We are completing the card industry's SAQ A self-assessment for this kind of setup and will sign the attestation each year.
Attestation, when signed
Accessibility, WCAG 2.2 AAVPAT / Accessibility Conformance Report
In progress, target Q4 2026
A full test of registration, volunteer signup, the document portal, public pages, and the admin console with a keyboard and a screen reader. The report will list every gap with a fix date.
Report, when published
CSA STAR Level 1Cloud Security Alliance registry
In progress, target Q1 2027
Our full security questionnaire, published in the Cloud Security Alliance's public registry where anyone can read every answer.
Registry entry, when listed
SOC 2 Type IIIndependent audit of security controls
In progress, target 2028
Our controls run on a documented schedule and we keep the evidence. The audit comes once that record is long enough to be worth auditing. Until the report exists, we won't say we have it.
Report, when issued
GDPREuropean privacy law
GDPR-ready
Built to GDPR principles: data minimization, explicit consent, deletion on request. We don't process EU or UK data today, so we don't claim compliance. If you need it, our Data Processing Agreement includes a Standard Contractual Clauses addendum before onboarding.
ISO/IEC 27001International security certification
Not pursued
Our SOC 2 controls are mapped to ISO 27001. We'll pursue certification when a client or partner needs it by name.
Our rule for this page: nothing here says “certified” or “compliant” unless a signed document exists and you can have a copy. When something is still a plan, it says so and carries a date.
Milton, Milton AI, and your data

Two names, one clear line: only Milton AI uses AI.

Milton sends your emails, with no AI involved

Confirmations, receipts, payment reminders, document requests, and deposit summaries go out from Milton, the automated assistant built into Karsenics. They are standard messages filled in from your records. They do not use AI, and nothing in them is sent to Anthropic.

Milton AI is the part that uses AI

Milton AI is an AI assistant built on a large language model: Claude, from Anthropic. It answers questions, builds lists, drafts memos, and explains parade lineup placements. It sees only what your organization has loaded: your event setup, the screen you are on, the agreements you upload, and registrations and money for team members who have access to them. Anthropic does not use what Milton AI is asked, or what it answers, to train its models.

Check before you rely on it

Milton AI can make mistakes. When an answer comes from the Karsenics guide or a document your organization uploaded, it links straight to that source. For money or deadlines, confirm the figure on its screen before you act. A memo Milton AI helps draft is sent by a person, under that person's name.

Turn Milton AI off, and it is off for everyone

Your Primary Administrator can turn off Milton AI in Event Setup. From then on nobody can use it for your organization, including Karsenics staff helping your account, and nothing from your organization is sent to Anthropic. Milton keeps sending your automated emails.

Privacy, in plain terms

Participants choose how they appear publicly: full listing, name only, or hidden. We collect what your event setup asks for and nothing more, we never sell data, and we never combine one organization's data with another's. Our Data Processing Agreement follows California and Texas privacy law and names every company that touches participant data.

Accessibility, honestly

We build to WCAG 2.2 Level AA as our standard. A full test across registration, volunteer signup, the document portal, public pages, and the admin console is scheduled for Q4 2026, and the report will list every gap with a fix date. We won't claim conformance before that test is done. If you hit a barrier now, tell us and we'll fix it.

Who touches the data

Every company involved, named.

We publish this list and give 30 days' notice before adding to it.

ProviderWhat they do for youWhereWhat they see
RenderHosts your isolated service, database, and backupsUnited StatesAll platform data, encrypted at rest
StripeProcesses card payments on your organization's own accountUnited StatesPayer name, email, amount, last four digits
PostmarkSends confirmations, receipts, and sign-in linksUnited StatesRecipient name, email, message content
BoldSignElectronic signatures, only if your organization uses themUnited StatesSigner name, email, signature record
AnthropicPowers Milton AI's answers and drafts. Not used to train their models. Receives nothing from an organization that has turned Milton AI offUnited StatesWhat Milton AI is asked and the records it reads to answer, which can include names and contact details

Running Karsenics itself

These support our own website and never receive participant data from the platform.

ProviderWhat they doWhat they see
VercelHosts the karsenics.com website you are readingSite visitor technical data
ResendDelivers messages sent through our contact pageWhat you type into the contact form
Google AnalyticsCounts visits to karsenics.com, with analytics storage denied by defaultSite visitor technical data
Documents on request

Need this for a board, a grant, or your city's IT team?

Ask and we'll send what we have: the Data Processing Agreement, our security policies (written, with formal adoption scheduled for Q4 2026), and each attestation as it's signed. Some documents go out under a simple confidentiality agreement.

Information Security PolicyIncident Response PlanBusiness Continuity PlanData Processing AgreementSubprocessor RegisterEach attestation, as it is signed

Found a security problem?

Tell us through the contact page and start your message with the word “security.” We read those first and reply within one business day, the same promise as every message through that page. We won't take action against anyone who reports in good faith. Our machine-readable contact details are published at the standard address security researchers check.

Report a security issue

# https://karsenics.com/.well-known/security.txt
Contact: https://karsenics.com/contact
Preferred-Languages: en
Canonical: https://karsenics.com/.well-known/security.txt
Policy: https://karsenics.com/trust