Skip to main content

    Security & AI trust

    Your pipeline data stays yours.

    Kondakta sits on top of your pipeline, so the first question we get from sales leaders and security reviewers is a fair one: what happens to our data, and what can the AI do on its own? Here is the honest answer, in plain terms.

    Kondakta never records, transcribes or listens to your calls, meetings or emails.

    Recommendations are built from the deal information you already keep — opportunities, contacts, activities and calendar entries — and every write waits for a person to approve it.

    Per-tenant data isolation

    Every customer's data lives in its own tenant. Your accounts, contacts, opportunities and activities are scoped to your organisation, and nothing crosses that boundary.

    • All records carry the tenant they belong to, enforced in the database rather than in application code.
    • Users only ever query inside their own tenant, whether from the app, an export or the API.
    • CRM credentials and calendar tokens are stored per tenant and never shared between customers.

    Row-level security

    Access is decided by the database on every single read and write, not by the screen you happen to be looking at.

    • Row-level security policies scope each table to the signed-in user and their tenant.
    • Team visibility is granted deliberately — a manager sees their team because the policy says so.
    • A missing or mistaken UI check cannot expose data the policy does not allow.

    Prompt and audit logging

    Everything the AI is asked and everything it proposes is recorded, so you can always answer "why did it say that?"

    • Each AI request is logged with the prompt, the model used and the response returned.
    • Record changes are audited with who made them, when, and whether they came from a person or an accepted recommendation.
    • Logs are retained per tenant and available to your administrators for review.

    Human approval before any write

    Kondakta proposes. You decide. Nothing is sent, changed or pushed to your CRM without a person approving it.

    • Follow-up drafts, MEDDIC scores and remediation sets are all presented for review first.
    • Salesforce write access is permission-gated, and every sync back is a deliberate action.
    • There are no unattended changes, nightly sweeps or autonomous sends.

    AI usage metering and daily budgets

    AI usage is metered per tenant and per user, with daily budgets so cost and behaviour stay predictable.

    • Every request is counted against your allowance before it runs.
    • Daily budgets cap spend and stop runaway usage from a single account or integration.
    • Administrators can see consumption and adjust allocations across the team.

    Rate limiting

    Requests are rate limited at the edge and inside the application, protecting both your data and the service.

    • Per-user and per-tenant limits on AI and API calls.
    • Abusive or looping traffic is throttled rather than allowed to degrade the service.
    • Sensitive endpoints carry tighter limits than ordinary reads.

    Admin-controlled templates and rules

    Your administrators own the guardrails the AI works inside — not individual reps, and not us.

    • Message templates, labels and follow-up rules are configured centrally.
    • Engagement thresholds — how long is too long between touchpoints — are set per team.
    • Changes to templates and rules are versioned and audited.

    Accessibility

    Kondakta and this website target WCAG 2.2 Level AA. Accessibility is treated as part of the product, not a retrofit.

    • Keyboard access to every workflow, with visible focus and skip-to-content links.
    • Colour contrast, text resizing and reduced-motion preferences respected throughout.
    • Issues can be reported at any time — see our accessibility statement for how.

    Our full accessibility statement and privacy policy carry the detail behind this page. Reviewing Kondakta for your team and need something specific? Get in touch.