live1,247 agents deployedbuilt by a solo devpowered by hermes
live1,247 agents deployedbuilt by a solo devpowered by hermes
Security & Compliance

Your data, your keys, your agent.

karpdo is built so that a platform-side mistake can never expose your API keys or customer conversations. Here is exactly how.

Encrypted keys, always

Every LLM API key is encrypted at rest with AES-256-GCM before it touches our database. Plaintext keys never leave your browser except over TLS to be encrypted.

Versioned, fingerprinted encryption

Every encrypted value carries a key-fingerprint. A misconfigured platform secret is detected and blocked automatically — it can never silently corrupt your key.

Per-tenant isolated agents

Every agent runs on its own dedicated virtual machine with its own filesystem and secret. There is no shared runtime between customers.

Bring your own key (BYOK)

Your usage is billed directly by your own LLM provider. karpdo never sees or marks up your token spend.

Authenticated machine endpoints

Every request to an agent machine — config, chat, backup — requires a per-agent secret. No public endpoint accepts unauthenticated writes.

Self-service data export

Export your full memory, message history, and configuration as JSON at any time from Settings — no support ticket required.

Data residency

Agent machines run in Singapore, the United States, Europe, or Japan, chosen automatically for the lowest latency to your customers. Your database lives in a single region for the lifetime of your account.

GDPR & PDPO requests

The self-service export in your dashboard covers GDPR Article 20 and Hong Kong PDPO Section 18 data-portability requests. For deletion requests, contact support — deletion is permanent and cannot be undone.

This page describes karpdo’s current architecture and is provided for informational purposes; it is not a compliance certification.