Komiti Security Sign in

Security and your data

Komiti asks for your ABN, your staffing, your wages and your certificates. Eventually it will ask to read your payroll. That is a lot to hand a small company, so here is exactly what happens to it — including the parts that aren't finished.

Where your data actually lives

Not "the cloud" — here are the specific answers, checked rather than assumed:

WhatWhereHow we know
Your account, business profile and obligationsCloudflare D1, region-pinned to Oceania (Sydney)The database reports region OC, colo SYD. Verified 6 Sep 2026.
Documents you upload to the vaultCloudflare R2, OceaniaThe bucket is created with location OC. Verified 6 Sep 2026.
The website itselfCloudflare's global edgePages are served from wherever you are. This is delivery, not storage — your data isn't copied there.
Anything you type into an AI toolSent to Anthropic (United States) to generate the answerNot used to train models. Named in the privacy policy.
Your sign-in emailsSent via Resend (United States)Named in the privacy policy.

How signing in works

There is no password. You enter your email, we email you a link, and the link signs you in. It works once and expires in twenty minutes. There is no password for anyone to leak, guess or reset — and Komiti never stores one.

The honest limitation: that means access to your Komiti account is exactly as strong as access to your email account. There is no second factor yet. If your email has two-factor turned on you are in good shape; if it doesn't, turn it on before you put anything sensitive in the vault.

What Komiti will never do with payroll access

The payroll half of the Guard will eventually ask to read your accounting data. Before that happens, these limits are written into the code as rules that throw errors, not as promises in a document:

These are covered by automated tests that run against the two real failures the feature was built from, so a future change that breaks one of them fails the build rather than shipping quietly.

When Komiti can't see something, it says so

A specific example, because it matters more than a general assurance. If Komiti can read your pay runs but cannot read your super payments, it will not tell you that you have a super shortfall — because "no payments visible" and "no payments made" are different facts, and only one of them is a problem. Reporting the wrong one would tell a director they are personally exposed when they may have paid on time. It reports the gap in the data instead.

What Komiti does not have yet

Listing these is more useful to you than omitting them:

Deleting your data

Ask and it's deleted — the whole account, or any single document. Email info@komiti.ai. Under Australian privacy law you can also ask what's held about you and have mistakes corrected; the privacy policy sets out that process and the complaint path to the OAIC if you are not satisfied.

Reporting a security problem

If you find a vulnerability, email info@komiti.ai with the details. You'll get a human reply, not a form. There is no bug bounty — Komiti has no revenue yet — but the report will be taken seriously and fixed, and you'll be told when it is.

Last reviewed 6 September 2026. If anything on this page stops being true, it gets changed rather than quietly left.