Canadian data residency
Core databases and processing in Montréal, Québec.
Enterprise Security
Karmaflow enforces identity, policy, and approval controls inside the same runtime where your workforce acts — anchored in Canadian infrastructure and Google Cloud’s defense-in-depth model.
Compliance posture
A snapshot of the controls and practices in place across the platform today.
Core databases and processing in Montréal, Québec.
Infrastructure aligned to Google’s enterprise security baseline.
Identity, access, and endpoint management for all internal systems.
Independently audited AI infrastructure partners under DPAs.
Internal controls reviewed and tested on a documented cadence.
Data governance
Canadian customers run on Canadian infrastructure by default — covered by PIPEDA. We accommodate alternative regions and regulatory frameworks for customers with specific requirements.
Canada · Montréal by default · alternative regions on request
AI APIs · no retention · no training, regardless of region
Compliance frameworks: PIPEDA covered by default for Canadian customers. GDPR-aligned handling, customer-specific obligations, and reduced-retention requirements are accommodated through your Data Processing Agreement.
Subprocessors
A limited set of independently audited providers, each bound by Data Processing Agreements that prohibit retention or use of client data for training.
| Subprocessor | Role | Data location |
|---|---|---|
| OpenAI | Large language model inference (GPT series) | USA |
| Google AI (Gemini) | Large language model inference (Gemini series) | USA |
| Deepgram | Real-time speech-to-text recognition | USA |
| Cartesia | Neural text-to-speech voice synthesis | USA |
| LiveKit | Real-time WebRTC voice infrastructure | USA |
| Twilio | SMS & voice communications delivery | USA |
| Mailgun | Transactional email delivery | USA |
API communications are encrypted in transit using TLS 1.3. Clients may request access to logs pertaining to their account or negotiate reduced retention windows where supported.
Runtime controls
The same loop runs around every agent action: stop what shouldn’t happen, route what needs review, and record everything that does.
Screen inputs, evaluate policy gates, verify scope, and block unauthorized actions before execution.
Identity, infrastructure & encryption
Every access decision — to infrastructure, data, or systems — is authenticated, authorized, and logged. Identity is the perimeter.
Documentation
A 5-page briefing covering infrastructure, data governance, subprocessors, identity controls, and organizational security practices — written for security and procurement teams.