Skip to content
Chat with us

Every number is yours. Every action is undoable.

Everything your crew leaves behind is locked tight.

Five things are true about how Kordis treats your business, and each one is built, tested, and checkable in the product today.

Last updated: August 4, 2026

01

Your workers' sensitive data is locked up the moment it arrives

02

Every look at sensitive data is written down

03

Your data leaves with you: whole, or not at all

04

Money numbers are never made up

05

Every answer shows its source, or says it can't

01

Your workers' sensitive data is locked up the moment it arrives

Social insurance numbers, birth dates, and bank details are sealed before they're stored. Nobody browses them. Not even us. Built and checkable: AES-256-GCM envelope encryption with keys held in Azure Key Vault; the database stores sealed references, never raw values.

02

Every look at sensitive data is written down

Any time anyone views a worker's sensitive details, Kordis records who looked, at what, and when. Permanently. Built and checkable: Append-only audit log on every sensitive-field access, with actor and purpose attached.

03

Your data leaves with you: whole, or not at all

Ask for an export and you get everything, readable. Ask for deletion and it's honored. Your records are never something we hold over you. Built and checkable: Built-in data-subject export and erasure flows, themselves audit-logged.

04

Money numbers are never made up

Every dollar figure you see comes from your own records. The part of Kordis that writes sentences is structurally unable to author a money number. Built and checkable: Deterministic money path: model-generated amounts are rejected by construction, not by review.

05

Every answer shows its source, or says it can't

Ask a question and the answer carries a tag you can click, opening the exact record it came from. No source, no claim: Kordis says "I can't verify that" instead of guessing. Built and checkable: Cited retrieval over your own records; uncited answers are refused at the engine level.

How Kordis uses AI

Kordis is designed around your approval. AI drafts messages, screens applicants, summarizes calls, recommends backfill options, and stages the work. Then an authorized person at your agency makes the call. Kordis does not independently send messages, place calls, assign workers, or touch pay. Every AI-assisted action that matters is staged first, logged, and tied to the records it came from. Your data is used only to run your own account: never sold, and never used to train or fine-tune the technology that powers Kordis.

How long we keep your data

Only as long as running your account and meeting the law require. Placements, timekeeping and payroll data stay while your account is active. Employment, wage and tax records carry minimum retention periods set by law, records of employment and provincial employment records among them, so those are kept for the period the law requires and we will tell you plainly when a deletion request touches one. Call recordings and transcripts follow your service agreement: ask for deletion and we remove our copies and instruct the calling and transcription companies to remove theirs, which finishes on their schedule rather than instantly. This is the posture PIPEDA expects, and the full schedule, subject by subject, is in the Privacy Policy.

What happens if you cancel

You export first, then it is deleted. Billing is month to month with no minimum term, so cancelling stops future renewals rather than starting a negotiation. After that you have thirty days to export your data, whole and readable, before the account is deleted. Fees already paid for the period you are in are not refunded, which is the one part of this that is worth knowing before you pick a date. Your records are never something we hold over you to keep you paying. The binding version is section 9 of the Terms.

Who else touches your data

11 named companies, and you can read the list. Each one is published with what it does, what data it touches and where it runs: hosting, sign-in, calling and texting, transcription, voice, email, background jobs, billing, product analytics and error monitoring. All of them run in the United States, including the Microsoft Azure hosting your workspace sits on. Your data is used only to run your own account, never sold, and never used to train or fine-tune the technology that powers Kordis. The register is the same one the Privacy Policy points at: see every company and what it handles.

Report a security issue

If you believe you've found a security vulnerability in Kordis, email info@kordisai.com with a clear description, steps to reproduce, and any supporting evidence. Please don't access, change, or download data that isn't yours while demonstrating an issue. We read every credible report, acknowledge it, and fix validated issues, and we'll tell you when it's resolved.

Running a vendor security review? Send your questionnaire and your client's compliance questions to us directly and we answer them straight, in writing. The full picture, including the boundaries Kordis holds by design, is at the trust centre.

See every claim in action.

In your trial workspace, you click the sources yourself, on your own data and your own records.

Run your real operation for two weeks. No card to start, nothing charged.

  • No card to start
  • Nothing charged
  • Cancel whenever
  • Guided setup
Security at Kordis: locked, logged, and yours