Legal
Karnot.Ai Security
Last updated: July 2026
Introduction
This page describes the security practices of Karnot Artificial Intelligence Pvt. Ltd. (“Karnot”, “we”, “us”, or “our”) in connection with the website karnot.ai (the “Site”) and our business operations. This page was last updated in July 2026, and should be read together with our Privacy Statement.
Karnot understands that the confidentiality, integrity, and availability of information are of fundamental importance to the organizations we work with. Karnot is committed to maintaining appropriate technological and operational security measures across our Site and our services.
Our Security Practices
Karnot has in place security processes designed to protect the information entrusted to us. These include, without limitation:
Encryption in transit.
All connections to the Site are encrypted using HTTPS/TLS. Information submitted through the Site, including enquiry and contact details, is transmitted over encrypted channels.
Access controls.
Access to personal information and client materials is restricted to authorized personnel on a need-to-know basis. Each individual having access to such information is obligated to maintain its confidentiality.
Client engagement security.
Materials shared with Karnot in the course of a client engagement are handled in accordance with the confidentiality terms of the applicable engagement agreement. Karnot does not use client materials for purposes other than those agreed with the client.
Third-party service providers.
Where Karnot engages third-party providers for hosting, infrastructure, or business operations, we select providers that maintain industry-standard security practices and bind them to appropriate confidentiality and data protection obligations.
Review and improvement.
Karnot reviews its security practices on an ongoing basis and updates them as appropriate in light of evolving threats, technologies, and legal requirements.
Although we take steps generally accepted as industry standard to protect information, no method of transmission over the internet or method of electronic storage is completely secure, and Karnot cannot guarantee absolute security.
Responsible Disclosure
Karnot values the work of security researchers and members of the public who identify and report potential vulnerabilities in good faith.
If you believe you have discovered a security vulnerability in the Site or in any Karnot system, we encourage you to report it to us at [email protected]. Please include a description of the issue, the steps required to reproduce it, and, where applicable, any relevant URLs, screenshots, or proof-of-concept material.
We ask that you: make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our services; do not access, modify, or retain data belonging to others; do not publicly disclose the vulnerability before we have had a reasonable opportunity to investigate and address it; and do not demand compensation as a condition of disclosure.
In turn, Karnot commits to acknowledging your report within a reasonable period, investigating in good faith, and not pursuing legal action against researchers who act in accordance with this policy. Karnot does not currently operate a paid bug bounty program.
Reporting Security Concerns
For any other security-related questions or concerns, including suspected phishing or impersonation of Karnot or its personnel, you may contact:
Karnot Artificial Intelligence Pvt. Ltd.[Registered office address]
[email protected]