Legal
Information Security Policy
Effective September 29, 2026
1. Purpose and scope
This policy describes the security principles Kabir AI ("Kabir AI", "we", "us"), formerly known as KabirTech Solutions, applies to kabirtechsolutions.com and to the software engagements we deliver for clients. It is a public summary of our approach, not an exhaustive technical specification.
2. Data we handle
On this website, the only personal information we actively collect is what you submit through the contact form: your name, work email, company, project type, budget range, and message. See our Privacy Policy for the full detail on what we collect and why.
For client engagements, the data we handle is defined by that engagement’s scope and governed by the client’s own agreement with us, not by this website.
3. Data in transit and at rest
This site is served over HTTPS/TLS, so information submitted through the contact form is encrypted in transit. Submissions are stored in our own PocketBase database on infrastructure we operate directly, not passed through a third-party CRM or marketing platform.
4. Access control
Access to systems holding client or prospect data is restricted to the Kabir AI staff who need it to do their job, on a least-privilege basis. Access is revoked promptly when someone’s role changes or their engagement with us ends.
5. Secure development practices
Client software we build follows the practices we’d want applied to our own systems: code review before merge, dependency and vulnerability scanning, environment separation between development and production, and secrets kept out of source control. Specific controls are agreed per engagement based on the sensitivity of the system being built.
6. Third-party services
This website loads a small number of external services: Google Fonts (fonts.googleapis.com / fonts.gstatic.com) for typefaces, and Hostinger CDN (images.hostinger.com, horizons-cdn.hostinger.com) for images. We don’t embed third-party analytics, chat widgets, or advertising pixels on this site.
For client engagements, any third-party infrastructure or subprocessor is disclosed and agreed as part of that engagement.
7. Employee and contractor practices
Everyone who works on client engagements, including engineers placed on dedicated teams, is bound by confidentiality obligations and is granted access to client systems on a need-to-know basis for the duration of the engagement.
8. Incident response
If we become aware of a security incident affecting personal data collected through this website, we will investigate promptly, take reasonable steps to contain and remediate it, and notify affected individuals or clients where required by law or by contract.
9. Responsible disclosure
If you believe you’ve found a security vulnerability affecting kabirtechsolutions.com, please report it to us at the email below before disclosing it publicly. Give us a reasonable amount of time to investigate and respond before sharing details with anyone else.
10. Changes to this policy
We may update this policy as our practices change. The date at the top reflects the most recent revision.
11. Contact us
Security questions or vulnerability reports: info@kabirtechsolutions.com, or write to Kabir AI, 1200 Congress Ave, Suite 460, Austin, TX.