Skip to main content
Kamboi

Trust and governance

Clear controls. Accountable decisions.

Kamboi is being designed around appropriate access, traceable decisions, and human oversight.

Kamboi is in development. Production security, supported identity options, integrations, and service commitments will be confirmed for the agreed release.

Engineering approach

Seven areas, in plain language.

Each area is being built now. Each one starts with why it matters to a buying organization.
  • Appropriate access to information

    A buyer, a requester and an accounts payable reviewer need different views of the same purchase.

    Access is scoped by organization and role, so people work with the procurement information their responsibilities require rather than everything stored in the system.

  • Server-enforced authority

    A control that only exists in the browser is not a control.

    Material decisions such as approvals and order changes are intended to be checked on the server against configured authority, not by hiding a button.

  • Review and separation of duties

    The person who requests something should not silently approve and receive it too.

    Where an organization configures it, review steps and separation of duties are intended to be part of the workflow rather than a manual habit.

  • Source records and decision history

    Six months later, someone will ask why this supplier at this price.

    Quotes, selections, orders, receipts and invoice questions stay connected to the purchase, with a history of who did what.

  • Controlled document access and handling

    Procurement documents contain commercially sensitive terms.

    Documents are tied to the records they support, and access follows the same rules as the rest of the purchase.

  • AI bounded by authorized context and human review

    Assistance that cannot be checked cannot be trusted.

    Assistance works from information the person may already see, shows its evidence and gaps, and never holds approval authority.

  • Defined integration and operational responsibilities

    Most disputes about controls are really about who owns which step.

    For any deployment, the integration boundaries and operational responsibilities are agreed explicitly rather than assumed.

What we do not claim

Absent scope, stated clearly.

None of the following is claimed for Kamboi today.
  • SOC 2 or ISO 27001 certification
  • GDPR or HIPAA compliance statements
  • A completed independent penetration test
  • Data residency guarantees
  • Service level agreements or 24/7 support
  • Certified integrations with named systems

Security and review questions

Write to abu@getkamboi.com.

We do not publish architecture internals, tenant identifiers or vulnerability reports on this website, and there is no trust report download or status dashboard to claim.

Reviewing Kamboi for your organization?

We can walk through the intended controls and be specific about what has not been verified yet.