Loading…
Legal
How we protect assessment and account data, written for someone doing a vendor review. It lists the controls we actually have — and, in section 6, the ones we do not, because a page that only lists strengths is not useful to you.
Last updated 1 August 2026 · Questions or complaints: team@kirnova.com
Every authorisation decision in the platform goes through a single evaluator rather than being scattered across screens. It is a pure function: given who is asking, what they want to do, and what they want to do it to, it returns a decision and a reason. Permissions are re-read from the database on every request — a session token carries an identity, never a role or a privilege level, so revoking access takes effect on the next request rather than when a token expires.
Reporting lines inside an organisation are structural information for display only. They are never a route to inherited permission: no authorisation decision walks a management hierarchy.
Where organisations embed our assessment in their own product, their data is isolated at the database level using row-level security, not only by application logic. One organisation’s records cannot be read through another’s, even if an application-layer check were missed.
Partner API keys are stored as hashes, so a copy of our database does not yield usable keys. API access is rate-limited per organisation, enforced in shared storage so the limit holds across all running instances rather than per-server.
What we hold, why, and for how long is set out in the Privacy Policy.
If you believe you have found a security issue, email team@kirnova.com with the subject line Security. Include enough detail to reproduce it.
We will acknowledge within 48 hours and keep you updated until it is resolved. Please give us a reasonable opportunity to fix an issue before disclosing it publicly, and do not access, modify or delete data belonging to anyone else while investigating. We will not pursue action against anyone who reports in good faith and follows those two conditions. We do not currently run a paid bug-bounty programme.
If a personal data breach occurs, we notify each affected person and the Data Protection Board of India, as the DPDP Act requires.
Stated plainly, because you would find out during a vendor review anyway and a page that hides it is worth less than one that does not.
If any of these is a requirement for your organisation, tell us at team@kirnova.com — knowing which ones actually block a deal is how they get prioritised.
Who you are dealing with
GrowBizx Brand Builders (operating as Kirnova)For any question about this document, a request about your personal data, or a grievance, email the address above. We acknowledge within 48 hours and respond substantively within 30 days. You can also reach us through the contact page.