SECURITY AND PROCUREMENT
Security and procurement
Karto connects how much housing is needed, how homelessness may change and what the required deeply affordable housing portfolio will cost.
Keep customer data purpose-limited.
DATA USE
Purpose-limited
Customer data supports the organization's modelling and planning.
Aggregate by design
Karto uses aggregate planning data, not individual client records.
Kept separate
Organization-scoped queries and PostgreSQL row-level security isolate each customer's data.
Not used to train AI models
Archer uses information to answer the request, not to train AI models.
Under customer control
Export or remove data on request.
Review the documented controls.
ACCESS AND AUDIT
Karto's documented controls include:
Secure password hashing
Short-lived sessions
Two-step verification
Microsoft Entra single sign-on
Owner, editor and viewer roles
Append-only activity records
Field names, not data values, in audit records
ENCRYPTION
Encrypt in transit and at rest.
Karto's documented design includes:
TLS encryption in transit
Azure-managed encryption at rest
Secrets stored in the runtime environment or Azure Key Vault
TECHNOLOGY
Check the stack.
Keep Archer grounded and controlled.
AI IN KARTO
Archer provides AI assistance within homelessness modelling.
-
Calculation engines produce consistent projections and financial results.
-
Archer receives only the aggregate scenario information needed for the question.
-
Suggestions are checked against budgets, program restrictions and validation rules.
-
Users review and approve every change.
Plan the procurement.
PROCUREMENT INFORMATION
See how Karto works.
Implementation
Four weeks includes setup, the first analysis and training.
Users
The standard licence includes three users with owner, editor and viewer roles.
Support
Monthly support is included; added analytical support is optional.
AVAILABLE DOCUMENTATION
Request the procurement package.
Access-control summary
Continuity and incident-response summaries
Terms, privacy terms and service levels
Accessibility statement or conformance report
The approved procurement package may include:
Security and technical overview
Data-flow diagram
Subprocessor list
Privacy and AI-use description
SECURITY QUESTIONS
Answer the review questions.
-
Aggregate community, program and project data.
-
Archer explains results, compares scenarios and tests options. Karto produces the projections; staff control changes.
-
It answers the request and is not used to train AI models.
-
Karto is hosted on Azure App Service.
-
Yes. Share your review requirements when booking a demo.
NEXT STEP
Book a Karto demo.
Review the product, implementation and security documentation.