Security and your data
Komiti asks for your ABN, your staffing, your wages and your certificates. Eventually it will ask to read your payroll. That is a lot to hand a small company, so here is exactly what happens to it — including the parts that aren't finished.
Where your data actually lives
Not "the cloud" — here are the specific answers, checked rather than assumed:
| What | Where | How we know |
|---|---|---|
| Your account, business profile and obligations | Cloudflare D1, region-pinned to Oceania (Sydney) | The database reports region OC, colo SYD. Verified 6 Sep 2026. |
| Documents you upload to the vault | Cloudflare R2, Oceania | The bucket is created with location OC. Verified 6 Sep 2026. |
| The website itself | Cloudflare's global edge | Pages are served from wherever you are. This is delivery, not storage — your data isn't copied there. |
| Anything you type into an AI tool | Sent to Anthropic (United States) to generate the answer | Not used to train models. Named in the privacy policy. |
| Your sign-in emails | Sent via Resend (United States) | Named in the privacy policy. |
How signing in works
There is no password. You enter your email, we email you a link, and the link signs you in. It works once and expires in twenty minutes. There is no password for anyone to leak, guess or reset — and Komiti never stores one.
What Komiti will never do with payroll access
The payroll half of the Guard will eventually ask to read your accounting data. Before that happens, these limits are written into the code as rules that throw errors, not as promises in a document:
- It will never move money. Paying super, approving a super batch, posting a payment and transferring funds are all blocked at the code level. Komiti stages work up to the approval button in your accounting system and stops. A person clicks it.
- It will never post to a closed financial year. Attempting to write into a finalised period raises an error rather than touching lodged accounts.
- Everything it writes is a draft. Offer letters, pay runs, minutes, emails — all marked as drafts for you to check and send yourself. Komiti does not send email on your behalf.
- It will read, not write, wherever reading is enough. Detection needs no write access at all.
These are covered by automated tests that run against the two real failures the feature was built from, so a future change that breaks one of them fails the build rather than shipping quietly.
When Komiti can't see something, it says so
What Komiti does not have yet
Listing these is more useful to you than omitting them:
- No professional indemnity insurance in place yet. It is being arranged, and no one will be charged before it is. Worth knowing if you are weighing how much to rely on the output.
- No independent security audit or certification. No SOC 2, no ISO 27001. Komiti is early and small, and claiming otherwise would be the exact kind of thing this page exists to avoid.
- No two-factor authentication beyond your email account, as above.
- The privacy policy and terms have not been reviewed by a lawyer yet. They are written honestly, but they are not a lawyer's work and they say so.
- One person operates this. Peter. There is no team with separate access, which is good for exposure and bad for bus factor. Be aware of both.
Deleting your data
Ask and it's deleted — the whole account, or any single document. Email info@komiti.ai. Under Australian privacy law you can also ask what's held about you and have mistakes corrected; the privacy policy sets out that process and the complaint path to the OAIC if you are not satisfied.
Reporting a security problem
If you find a vulnerability, email info@komiti.ai with the details. You'll get a human reply, not a form. There is no bug bounty — Komiti has no revenue yet — but the report will be taken seriously and fixed, and you'll be told when it is.
Last reviewed 6 September 2026. If anything on this page stops being true, it gets changed rather than quietly left.