The KitSlate platform (the “Service”) is operated by MIXEL INC, a corporation organised under the laws of the State of New York, United States, doing business as KitSlate (“MIXEL INC,” “KitSlate,” “we”). This document applies to the production systems that deliver the Service at kitslate.app and to Customer Data processed within them.
“Customer Data” means the equipment records, productions, documents, client and crew records, uploaded files and related information that a Customer or its authorised users submit to the Service. Capitalised terms not defined here have the meaning given in the Terms & Conditions.
Customer Data is stored in a managed PostgreSQL database and object store operated by Supabase on Amazon Web Services infrastructure in region us-east-1, in the United States. The web application is delivered by Cloudflare, and the serverless functions supporting integration and AI-assisted features execute on Cloudflare’s network.
Customers located outside the United States should refer to Section 21 of the Privacy Policy, which sets out the transfer mechanisms applicable to international transfers of personal information.
The Service is multi-tenant. The following controls govern separation between Customer workspaces:
The Service does not implement password-based authentication. Users authenticate either through Google OAuth or through a single-use code delivered to the email address on the account. Accordingly, MIXEL INC does not collect, store or transmit user passwords, and no password credential store exists within the Service.
The security of a KitSlate account is therefore dependent on the security of the identity provider or mailbox used to authenticate. Customers are advised to enable multi-factor authentication with that provider. Sessions are maintained using short-lived tokens subject to refresh, and are revoked on sign-out. The Service does not currently offer a native second authentication factor; see Section 13.
Subscription payments and, where enabled by the Customer, online invoice payments are processed by Stripe, Inc., a PCI DSS Level 1 certified service provider.
Payments between a Customer and that Customer’s own clients are transacted between those parties. MIXEL INC is not a party to them and does not hold Customer funds. See Section 14 of the Terms & Conditions.
Customer workspaces are backed up on a nightly schedule, encrypted prior to storage, and retained as versioned history subject to a rolling pruning cycle under which deleted records are generally removed from backup within 30 days. The infrastructure provider additionally maintains point-in-time database snapshots.
Restoration procedures are executed and verified rather than assumed. Independently of MIXEL INC’s own controls, Customers may export a complete workspace archive at any time, together with record-level exports in CSV and PDF format. MIXEL INC treats the availability of Customer-controlled export as a standing entitlement of the Service rather than a discretionary accommodation.
Outbound mail is transmitted by Resend from a verified sending domain. SPF, DKIM and DMARC records are published in DNS to permit recipient verification of messages purporting to originate from KitSlate. Inbound replies to documents sent through the Service may be routed to the originating workspace using a per-document token address; those tokens are randomly generated, single-purpose, and convey no account credential.
Email is not a confidential transmission channel and is not represented as one. A document transmitted by email passes outside the Service’s control on delivery, and any link contained in it is accessible to any party holding that link. Customers are responsible for controlling onward distribution.
Certain optional features — receipt and document interpretation, catalogue matching, import column mapping and drafting assistance — transmit the specific item submitted by the user to Anthropic PBC over TLS and return the generated result. Transmission occurs only on user invocation of the relevant feature and is limited to the submitted item; the Service does not transmit workspace data to a model provider on a background or bulk basis.
Under Anthropic’s commercial API terms, inputs and outputs are not used to train its models. MIXEL INC does not use Customer Data to train, fine-tune or improve any machine-learning model, and does not license Customer Data to any party for that purpose. AI-generated output is advisory and requires review by the Customer before reliance.
Changes to the Service are governed by a controlled release process, which MIXEL INC treats as a security control:
Access to production systems is restricted to personnel with an operational requirement for it, is exercised through the authenticated administrative consoles of the relevant infrastructure providers subject to those providers’ access controls and logging, and is used for operation and support of the Service. Credentials and API keys are held as managed secrets within the platforms that require them and are not committed to source control; an automated control fails the build in the event that a credential is introduced into the codebase.
MIXEL INC maintains an incident response process under which incidents are recorded, root cause is determined, and resulting controls are incorporated into the automated certification pipeline rather than retained as procedural guidance.
In the event MIXEL INC becomes aware of a breach affecting personal information, it will notify affected Customers without undue delay and in any event within the period required by applicable law, and will provide the nature of the incident, the categories and approximate volume of data concerned, the likely consequences, the measures taken or proposed, and recommended actions for the Customer.
MIXEL INC states the following for the avoidance of doubt in procurement and security review:
This statement is maintained as the assurance position changes.
Suspected vulnerabilities should be reported to [email protected] with sufficient detail to permit reproduction. MIXEL INC will acknowledge the report, provide status updates, and credit the reporter where requested. MIXEL INC does not currently operate a paid vulnerability reward programme.
Safe harbour. Where research is conducted in good faith and within the conditions below, MIXEL INC will not pursue or support legal action in respect of that research, and such testing does not constitute a breach of the Terms & Conditions. Researchers must:
The subprocessors engaged in the delivery of the Service, together with the processing each performs and its processing location, are set out in Section 20 of the Privacy Policy. Each subprocessor is engaged under contractual terms requiring it to process data only on MIXEL INC’s documented instructions. The list is updated in advance of the engagement of any new subprocessor that processes personal information.
The security of the Service depends in part on controls exercised by the Customer. Customers are responsible for the following:
Security reports and enquiries: [email protected]. Data protection enquiries and rights requests: [email protected]. All other enquiries: [email protected].
MIXEL INC
a New York corporation, doing business as KitSlate
State of New York, United States
[email protected] · kitslate.app