Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.




Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.

CSAI FoundationChaptersEventsBlog

CSA STAR Registry

Security, Trust, Assurance, and Risk Registry

Listings for Kalisme

Listings for Kalisme

Kalisme is a sole proprietorship based in Lausanne, Switzerland. It publishes Kalisme, a personal development application for iPhone and Apple Watch, and the services supporting it: the kalisme.com website, a relay to a third party language model for the in-app companion, an end to end encrypted relay for its support messaging, a telemetry pipeline, and Kalisme Pro, through which organisations administer seats for their staff.

Its security posture is carried by architecture rather than procedure, and is verifiable rather than promised. The service holds no user account, no directory and no user password. Personal content is encrypted on the device with a key Kalisme never holds, so it cannot produce that content, even under legal compulsion. Support messages between relatives are end to end encrypted, and the relay forwards ciphertext it cannot read. No third party SDK or advertising tracker is embedded, and website audience measurement uses no cookie, no identifier and no clear text IP address.

Hosting is in the European Union, at OVHcloud in France and Hetzner in Germany, both certified ISO/IEC 27001. One transfer leaves that perimeter, to a language model provider in the United States. It is disclosed in fifteen languages, with consent collected before any message is sent.

Kalisme holds no external certification, runs no penetration test and has no formalised continuity plan. These gaps are named in its CAIQ rather than hidden.

Kalisme

Scope of this assessment: the Kalisme service as delivered to individual users and to professional customers. In scope: the iOS and Apple Watch ap...

Listed Since: 2026-08-25

CAIQ
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).