— TRUST & SECURITY

Check our security yourself.

Every claim here comes with a way to check it, starting with these headers.

HTTPS only · a published CSP · eight named vendors

Response headers · carna.ai

strict-transport-security
max-age=63072000; includeSubDomains; preload
content-security-policy
default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'self'; …
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
referrer-policy
strict-origin-when-cross-origin
permissions-policy
camera=(), microphone=(), geolocation=()

Every page on carna.ai is served with these. Open your browser's network tab on this page and read them back.

— SECURITY POSTURE

What we can show you.

Six choices already in place, each with the way to check it yourself.

  • HTTPS only, enforced by the browser

    Every page travels over TLS, and a two-year HSTS header covering our subdomains tells a browser that has seen the site once to refuse anything else.

    Network tab → strict-transport-security

  • A locked-down browser surface

    A Content-Security-Policy names every third party the site may load and the browser blocks the rest. Camera, microphone and location are denied outright.

    Network tab → content-security-policy

  • Access follows the role

    Teachers and learners sign in to different apps: a learner opens the work assigned to them, a teacher their classes and reports.

    See both apps, pictured below

  • A bot check on every form

    Cloudflare Turnstile checks each submission, and its script loads only when you press send, not while you read.

    Network tab → challenges.cloudflare.com, only after send

  • Measurement, kept narrow

    Google's tags start with every consent signal denied, and PostHog runs on its EU cloud through carna.ai, honours Do Not Track and records no sessions.

    Network tab → analytics calls go to carna.ai/ingest

  • A published way to report a problem

    security@carna.app is published in our security.txt, so a researcher never has to guess where to send a report.

    carna.ai/.well-known/security.txt

— COMPLIANCE

Honest about where we stand.

  • GDPR Followed

    Carna Technologies Ltd is the contracting entity outside Turkey. We follow the GDPR for personal data, and a Data Processing Addendum (DPA) is available on request.

  • KVKK Followed

    Carna Eğitim Teknolojileri A.Ş. is the contracting entity in Turkey, working to KVKK requirements for the Turkish market.

  • COPPA Observed

    We observe COPPA, the US rules for collecting data from children under 13, for Carna for kids. Ask us for the specifics your review needs. See Carna for kids

  • SOC 2 Type II In progress

    We are working toward SOC 2 Type II — it is on our roadmap and in progress. We do not claim to be SOC 2 certified today, and we'll update this page when that changes.

This page was last reviewed on 16 September 2026.

— ACCESS BY ROLE

Each role gets its own view.

These are the two apps, not illustrations of them: the same school, two sign-ins, two different views.

  • TEACHER APP

    Their classes and reports

    A teacher opens the class they teach and reads it course by course, each course ranked by its average score.

    Reports in the Carna teacher app. Carna School London is a sample school; the class and the scores are demo data.

  • STUDENT APP

    Their own work

    A learner opens their own home: the work assigned to them, soonest due first, and what their teacher shared with the class.

    A learner's home in the Carna student app. Carna School London is a sample school; the assignments and dates are demo data.

— SUB-PROCESSORS

Every vendor this site uses.

Every third party that loads on carna.ai today, plus the tool that tells our team about a form. The policy also allows YouTube, Vimeo and Wistia on a page that embeds a video, and carna.app, our own product. Ask us for the list that covers Carna for Organizations; it comes with the DPA.

Vendor What it does When it runs
Cloudflare Hosts and serves this site from its edge network. Every page
Cloudflare Turnstile Checks that a form submission comes from a person. When you submit a form
PostHog Product analytics for this site, on its EU cloud, proxied through carna.ai. Honours Do Not Track; no session recording. After you accept analytics
Sentry Collects JavaScript errors so we can fix them, in its EU (Germany) region, with session replay off. Every page
Google Tag Manager, Analytics & Ads Measures which pages and campaigns bring people here. Its consent signals start denied; cookies only after you accept. Every page, once idle
Helpway Runs the support chat, including its first AI reply. Every page, once idle
better-i18n Hosts the site's translations and blog content, which pages are built from. At build time only
Slack Tells our team about each form submission, with the details you entered. When you submit a form

— DOCUMENTS

Read it here, or ask for more.

— FAQ

Questions people ask.

Four questions a security review usually starts with. If yours is not here, send it to us.

How is my data kept private?

Traffic to carna.ai runs over TLS only, enforced by an HSTS header. Inside the product, access follows the role you hold. A Content-Security-Policy limits which third parties the site can load, and Google's tags set no analytics or advertising cookies until you accept. A Data Processing Addendum is available on request.

Where is my data stored?

The website you are reading is served from Cloudflare's edge network. Where your product data is stored, and where it may be transferred, is set out in our Data Processing Addendum — ask us for it and we will send it with the sub-processor list that covers Carna for Organizations itself. Carna Technologies Ltd is the contracting entity outside Turkey and Carna Eğitim Teknolojileri A.Ş. inside it.

Who can access my data?

Access follows the role: a learner opens the work assigned to them, a teacher their classes and reports. For single sign-on, automated provisioning or anything your IT team has to sign off, talk to us — we would rather scope it with you than list capabilities here that we have not shipped.

Are you SOC 2 certified?

Not yet. SOC 2 Type II is on our roadmap and in progress. We would rather be honest about where we are than claim a certification we do not hold, and we'll update this page the moment that status changes.

Security questions before you commit?

Procurement, data residency, or a DPA review — tell us what your team needs and we'll get the right answers to you.