Security & Data Privacy Overview
How makat.ai protects your procurement data
Our Commitment to Customer Trust
makat.ai is designed for mission-critical procurement workflows. We understand that customers entrust us with sensitive purchasing, pricing, and BOM data, and we treat this responsibility with the highest priority. Our platform is built with security-by-design principles, minimal attack surface, and strict data isolation between customers.
Platform Model & Architecture
- Hosted on Amazon Web Services (AWS) in the US-East region
- Built entirely on managed cloud services (e.g., AWS Lambda, API Gateway)
- No customer-managed servers, agents, or local installations
- Planned expansion to EU-based cloud infrastructure (Google Cloud) to support regional requirements
This architecture significantly reduces operational and security risks by eliminating long-lived servers and minimizing exposed infrastructure.
Data We Handle (and How We Use It)
makat.ai processes procurement-related business data strictly for tactical purchasing workflows, including:
- Company profiles
- Purchase Orders (POs)
- Requests for Quotation (RFQs)
- Pricing and sourcing history
- ✓Customer data is never shared with other customers
- ✓Data is not sold, rented, or exposed to third parties
- ✓All data remains logically isolated per company
AI Providers & Data Usage
makat.ai does not use consumer AI tools such as ChatGPT, Gemini Chat, or any public-facing AI applications. Instead, we integrate directly with enterprise AI APIs provided by leading vendors:
- OpenAI GPT models (via paid API access)
- Google Gemini models (via paid API access)
This means we use the underlying AI models, not the public chat products. All access is governed by commercial API agreements: customer data sent to these APIs is not used to train public models, is processed only to generate responses for your workflows, and no prompts or outputs are made public or reused across customers.
ChatGPT / Gemini Chat
- ✕Consumer products
- ✕User data may be retained or used depending on settings
GPT & Gemini APIs (what makat.ai uses)
- ✓Enterprise-grade, paid APIs
- ✓No training on customer data
- ✓Covered by strict data-protection terms
makat.ai never uploads customer data to public tools, and no employee manually pastes customer information into consumer AI interfaces.
Our Internal AI Safeguards
- Only the minimum required data is sent to AI services
- Sensitive fields are filtered or abstracted where possible
- All AI interactions occur within makat.ai's controlled backend
- Outputs are scoped strictly to the requesting customer's environment
Authentication & Access Control
- Passwordless authentication via secure magic links sent to verified email addresses
- No passwords stored or managed by the platform
- Access is restricted to authorized company users only
- Internal access follows least-privilege principles
Encryption & Secure Communications
- All traffic is protected using HTTPS with TLS, managed by AWS API Gateway v2
- Encryption in transit is enforced by default
- Cloud-native security controls are applied consistently across the platform
Monitoring, Logging & Auditability
- Every access and every API (RPC) call is logged
- Centralized monitoring and alerting via Sentry
- Continuous visibility into system behavior and anomalous activity
- This enables rapid detection and response to any unexpected behavior
Incident Handling & Risk Reduction
- makat.ai uses fully managed infrastructure, eliminating common attack vectors such as exposed servers or unmanaged operating systems
- The platform's serverless design minimizes the overall attack surface
- Any security incident is handled immediately by the engineering team
- Our focus is on prevention, fast detection, and rapid mitigation
Standards, Quality & Industry Trust
- ISO 9001:2015 certified (quality management)
- Active member of ERAI, supporting supply-chain risk mitigation and supplier integrity
- Continuous internal reviews of security and data-handling practices
What This Means for Customers
- ✓Your procurement data stays private and isolated
- ✓Your data is not shared or reused across customers
- ✓Your information is protected by modern cloud security controls
- ✓The platform is designed to reduce cyber-attack exposure by default
Transparency
makat.ai is committed to transparency and open dialogue. We are happy to discuss our security architecture, data handling practices, or future compliance initiatives with prospective customers.