Your participants' data, handled like it's ours.
Every organization on Karsenics runs on its own isolated service. Nobody sees another organization's people, money, or plans, and card numbers never touch us. This page says exactly what we do, what we've had checked, and what's still in progress. Where a document backs a claim, you can ask for it.
Last reviewed September 2026 · reviewed quarterlyFour things you can count on before you read anything else.
These aren't goals. They're how the platform is built and run right now.
Your organization is on its own island.
Each organization gets its own service, its own storage, and its own database, hosted in the United States and encrypted at rest and in transit. There's no shared database and no switch that could show one organization another's data, because the data isn't in the same place.
Named people, no passwords to leak.
Your team signs in with a one-time link to their email. There's no password to reuse or steal. Your Primary Administrator decides who can see money, send messages, or change registrations, and can switch anyone off in one click.
Payments go to Stripe, never through us.
When a participant pays, they're handed to Stripe's own checkout page. Stripe is certified at the highest level of the card industry's security standard. Card numbers never reach Karsenics; we receive a payment confirmation. We're completing the card industry's self-assessment for this kind of setup, and we'll sign it every year.
Backed up every day. Restored on purpose, not just hoped for.
Your data is snapshotted daily and kept encrypted. On July 21, 2026 we restored a backup end to end and checked it, because a backup nobody has tested is a hope. From Q4 2026 that test is scheduled every quarter, with each result recorded.
Where we stand, without the badge wall.
Some of these we do ourselves and document. Some need an outside auditor. Most are in progress today, and each one says so with a date.
Two names, one clear line: only Milton AI uses AI.
Milton sends your emails, with no AI involved
Confirmations, receipts, payment reminders, document requests, and deposit summaries go out from Milton, the automated assistant built into Karsenics. They are standard messages filled in from your records. They do not use AI, and nothing in them is sent to Anthropic.
Milton AI is the part that uses AI
Milton AI is an AI assistant built on a large language model: Claude, from Anthropic. It answers questions, builds lists, drafts memos, and explains parade lineup placements. It sees only what your organization has loaded: your event setup, the screen you are on, the agreements you upload, and registrations and money for team members who have access to them. Anthropic does not use what Milton AI is asked, or what it answers, to train its models.
Check before you rely on it
Milton AI can make mistakes. When an answer comes from the Karsenics guide or a document your organization uploaded, it links straight to that source. For money or deadlines, confirm the figure on its screen before you act. A memo Milton AI helps draft is sent by a person, under that person's name.
Turn Milton AI off, and it is off for everyone
Your Primary Administrator can turn off Milton AI in Event Setup. From then on nobody can use it for your organization, including Karsenics staff helping your account, and nothing from your organization is sent to Anthropic. Milton keeps sending your automated emails.
Privacy, in plain terms
Participants choose how they appear publicly: full listing, name only, or hidden. We collect what your event setup asks for and nothing more, we never sell data, and we never combine one organization's data with another's. Our Data Processing Agreement follows California and Texas privacy law and names every company that touches participant data.
Accessibility, honestly
We build to WCAG 2.2 Level AA as our standard. A full test across registration, volunteer signup, the document portal, public pages, and the admin console is scheduled for Q4 2026, and the report will list every gap with a fix date. We won't claim conformance before that test is done. If you hit a barrier now, tell us and we'll fix it.
Every company involved, named.
We publish this list and give 30 days' notice before adding to it.
| Provider | What they do for you | Where | What they see |
|---|---|---|---|
| Render | Hosts your isolated service, database, and backups | United States | All platform data, encrypted at rest |
| Stripe | Processes card payments on your organization's own account | United States | Payer name, email, amount, last four digits |
| Postmark | Sends confirmations, receipts, and sign-in links | United States | Recipient name, email, message content |
| BoldSign | Electronic signatures, only if your organization uses them | United States | Signer name, email, signature record |
| Anthropic | Powers Milton AI's answers and drafts. Not used to train their models. Receives nothing from an organization that has turned Milton AI off | United States | What Milton AI is asked and the records it reads to answer, which can include names and contact details |
Running Karsenics itself
These support our own website and never receive participant data from the platform.
| Provider | What they do | What they see |
|---|---|---|
| Vercel | Hosts the karsenics.com website you are reading | Site visitor technical data |
| Resend | Delivers messages sent through our contact page | What you type into the contact form |
| Google Analytics | Counts visits to karsenics.com, with analytics storage denied by default | Site visitor technical data |
Need this for a board, a grant, or your city's IT team?
Ask and we'll send what we have: the Data Processing Agreement, our security policies (written, with formal adoption scheduled for Q4 2026), and each attestation as it's signed. Some documents go out under a simple confidentiality agreement.
Found a security problem?
Tell us through the contact page and start your message with the word “security.” We read those first and reply within one business day, the same promise as every message through that page. We won't take action against anyone who reports in good faith. Our machine-readable contact details are published at the standard address security researchers check.
# https://karsenics.com/.well-known/security.txt Contact: https://karsenics.com/contact Preferred-Languages: en Canonical: https://karsenics.com/.well-known/security.txt Policy: https://karsenics.com/trust
