Last updated: April 2026 · Kontrable is an early-stage product in open beta.
Kontrable is contractor management software. We help businesses organize contractor onboarding, manage contracts, track invoices, and record payments. We are not a payment processor, employer of record, or financial institution. We never hold or route money.
We keep our subprocessor list minimal. Each service listed below processes some form of customer or contractor data as part of operating the platform.
| Service | Role | Data involved |
|---|---|---|
| Supabase | Database & auth | User accounts, contractor profiles, contracts, payment records |
| Veriff | Identity & business verification (KYC/KYB) | ID documents, selfies, business registration — processed by Veriff, not stored by Kontrable |
| SignatureAPI | Electronic signatures | Contract documents, signature events |
| Resend | Transactional email | Email address, notification content |
| Stripe | Billing & subscriptions | Payment info handled entirely by Stripe — not stored by Kontrable |
| Vercel | Hosting & CDN | No persistent customer data — request routing only |
| Cloudflare | DNS, WAF, DDoS protection | No customer data stored — network security layer only |
Every contractor on Kontrable verifies their identity before they can access a contract or submit a payment request. This protects both businesses and contractors.
Individual contractors complete identity verification powered by Veriff. The process includes a government-issued ID scan and a live selfie match. Verification typically completes in under two minutes. Kontrable receives a pass/fail result; the raw identity documents are processed and retained by Veriff under their own data policies.
Business contractors (service companies, studios, registered entities) complete business verification including company registration documents and beneficial ownership confirmation. This ensures you know who you're paying and that the entity is legitimate.
For agent-based contractors — humans or businesses operating AI agents on contract — the operator completes standard KYC or KYB verification. The contract and all legal obligations are with the operator, not the agent. Kontrable treats agent operators with the same verification requirements as any other contractor type.
Kontrable does not make legal determinations about employment status. We provide compliance infrastructure. You remain responsible for ensuring your contractor relationships are structured appropriately under applicable law.
Contracts on Kontrable are created using templates (NDA, SOW, general contractor agreement) or written from scratch. AI-assisted contract generation is available using your business context and the contractor's location and type.
Electronic signatures are handled through SignatureAPI. Both parties receive a legally binding signed copy immediately upon completion. Contracts are stored in Kontrable and can be exported at any time.
Kontrable does not provide legal advice and does not guarantee that any specific contract template meets legal requirements in your jurisdiction. Have contracts reviewed by a qualified legal professional for your specific situation.
Kontrable never holds, routes, or touches your money. Payments go directly from your bank account, Wise, PayPal, Payoneer, or any other method you use, straight to your contractors. Kontrable runs alongside to record the transaction, confirm amounts, and notify both sides in real time.
Kontrable automatically generates an immutable pay stub PDF at the moment of payment confirmation. The year-to-date total is captured at that moment and never retroactively updated. This gives both parties a clean, timestamped record of every payment.
Kontrable is built with GDPR principles in mind. We collect only the data necessary to operate the platform. No tracking pixels, no third-party advertising integrations, no sale of personal data.
Our analytics tools (Fathom, Google Analytics) are configured without advertising features. No personally identifiable information is shared with advertising networks.
For Data Processing Agreement (DPA) requests, contact us at privacy@kontrable.com.
Kontrable is in open beta. We are an early-stage product and honest about what we have and haven't yet formalized.
| Item | Status |
|---|---|
| SOC 2 Type II | Planned |
| ISO 27001 | Planned |
| Third-party penetration test | Planned |
| GDPR compliance practices | Active |
| Encrypted data at rest (AES-256) | Active |
| TLS in transit | Active |
| Identity verification via Veriff | Active |
| Cloudflare WAF & DDoS protection | Active |
Our infrastructure providers (Supabase on AWS, Vercel) maintain their own SOC 2 Type II compliance. We will publish our own formal certifications as the product matures.
If you discover a security vulnerability in Kontrable, please report it responsibly to security@tarkle.com.
For general security questions not covered here, contact us at kontrable.com/contact.