Trust and governance
Clear controls. Accountable decisions.
Kamboi is being designed around appropriate access, traceable decisions, and human oversight.
Kamboi is in development. Production security, supported identity options, integrations, and service commitments will be confirmed for the agreed release.
Engineering approach
Seven areas, in plain language.
Appropriate access to information
A buyer, a requester and an accounts payable reviewer need different views of the same purchase.
Access is scoped by organization and role, so people work with the procurement information their responsibilities require rather than everything stored in the system.
Server-enforced authority
A control that only exists in the browser is not a control.
Material decisions such as approvals and order changes are intended to be checked on the server against configured authority, not by hiding a button.
Review and separation of duties
The person who requests something should not silently approve and receive it too.
Where an organization configures it, review steps and separation of duties are intended to be part of the workflow rather than a manual habit.
Source records and decision history
Six months later, someone will ask why this supplier at this price.
Quotes, selections, orders, receipts and invoice questions stay connected to the purchase, with a history of who did what.
Controlled document access and handling
Procurement documents contain commercially sensitive terms.
Documents are tied to the records they support, and access follows the same rules as the rest of the purchase.
AI bounded by authorized context and human review
Assistance that cannot be checked cannot be trusted.
Assistance works from information the person may already see, shows its evidence and gaps, and never holds approval authority.
Defined integration and operational responsibilities
Most disputes about controls are really about who owns which step.
For any deployment, the integration boundaries and operational responsibilities are agreed explicitly rather than assumed.
What we do not claim
Absent scope, stated clearly.
- SOC 2 or ISO 27001 certification
- GDPR or HIPAA compliance statements
- A completed independent penetration test
- Data residency guarantees
- Service level agreements or 24/7 support
- Certified integrations with named systems
Security and review questions
Write to abu@getkamboi.com.
We do not publish architecture internals, tenant identifiers or vulnerability reports on this website, and there is no trust report download or status dashboard to claim.
Reviewing Kamboi for your organization?
We can walk through the intended controls and be specific about what has not been verified yet.