KKAIROS
Governance framework · 2026
Corporate Governance Handbook

Clarity to move with confidence.

Governance · Accountability · Technology · Clinical Operations · Information · Finance · Intellectual Property

Document ownerOffice of the CEO
Applies toDirectors, officers, employees, consultants, contractors, and other authorized representatives of Kairos
Browse the handbook

This handbook defines how Kairos operates, who owns what, where authority sits, and how information, technology, clinical work, money, contracts, and intellectual property are governed.

Part I

Corporate Governance

Chapters 01–03
Chapter 01

Governance Principles & Rules of the Road

Establishes the fundamental principles under which Kairos operates.

Core principles

  • Kairos business belongs to Kairos.
  • Authority comes with accountability.
  • Confidentiality does not mean concealment.
  • Access is based on role and legitimate need.
  • Material information must travel upward.
  • Decisions affecting the company must be documented.
  • No individual owns a client, project, study, system, dataset, or corporate relationship.
  • Company interests take precedence over individual control of information.
  • Regulatory and contractual restrictions must always be respected.
  • When authority is unclear, escalate before acting.
Chapter 02

Corporate Authority & Delegation

Defines who may make which decisions on behalf of Kairos.

Establish a formal Delegation of Authority covering

  • Board
  • CEO
  • Executive leadership
  • Clinical leadership
  • Technology leadership
  • Finance
  • Business development
  • Project/study leadership
  • Employees and contractors

Specify authority for

  • Signing contracts
  • Pricing
  • Hiring
  • Termination
  • Purchasing
  • Vendor engagement
  • Client commitments
  • Study commitments
  • Technology procurement
  • Software subscriptions
  • Financial expenditure
  • Regulatory representations
  • Access to sensitive systems

Principle: No one may commit Kairos beyond their delegated authority.

Chapter 03

Corporate Records & Communications

Defines what constitutes an official Kairos record.

Company records include

  • Kairos-domain email
  • Contracts
  • Proposals
  • Client correspondence
  • Study documentation
  • Meeting decisions
  • Financial records
  • Technology documentation
  • Source code
  • Databases
  • Company messaging
  • Approved WhatsApp business communications
  • Documents created while performing Kairos work

Material decisions made verbally, through WhatsApp, or through another informal channel must be appropriately captured in the corporate record.

Part II

Clinical & Regulatory Governance

Chapters 04–06
Chapter 04

Clinical Trial Governance

Establishes the distinction between:

Corporate oversight  ↔  study-level authorized access

Kairos leadership must have sufficient information to understand:

  • What study Kairos is participating in
  • Who the sponsor/client is
  • What Kairos has contracted to do
  • Who is responsible
  • Major milestones
  • Financial implications
  • Operational status
  • Material risks
  • Regulatory obligations

Access to blinded data, PHI, PII, patient-level data, investigational information, or otherwise restricted study information remains role-based and governed by applicable regulations, agreements, protocols, and SOPs.

Chapter 05

Confidentiality, Privacy & Information Classification

Create formal information classifications:

PUBLICInformation approved for public distribution.
INTERNALRoutine Kairos business information.
CONFIDENTIALCommercial, operational, financial, client, or proprietary information.
RESTRICTEDHighly sensitive information requiring explicitly authorized access.

Restricted examples

  • PHI/PII
  • Blinded clinical data
  • Passwords
  • Security credentials
  • Certain sponsor information
  • Investigational information
  • Highly sensitive financial or personnel information

Access should follow the minimum necessary / need-to-know principle.

Chapter 06

Quality, Compliance & Escalation

Defines issues that must immediately be escalated.

Examples include

  • Patient safety concerns
  • Protocol deviations
  • Data-integrity concerns
  • Privacy breaches
  • Security incidents
  • Regulatory concerns
  • Sponsor complaints
  • Serious study delays
  • Contract violations
  • Suspected misconduct
  • Financial irregularities
Kairos Rule: Bad news travels upward quickly.

No employee should conceal a material problem because they believe they can resolve it themselves.

Part III

Technology Governance

Chapters 07–14
Chapter 07

Technology Ownership

This should be unequivocal.

Technology created for Kairos using Kairos resources or within the scope of employment/contractual duties is governed by the applicable employment, contractor, IP, and development agreements and, where assigned to Kairos, is a Kairos corporate asset.

This may include

  • Source code
  • Applications
  • Databases
  • APIs
  • Algorithms
  • AI prompts
  • AI workflows
  • Agents
  • Documentation
  • Architecture
  • Infrastructure configuration
  • Deployment configuration
  • Automation
  • Analytics
  • Internal tools

No production technology should depend exclusively upon one individual's personal account or personal infrastructure.

Chapter 08

Source Code & Repository Governance

All official software must reside in company-controlled repositories.

Establish standards for

  • GitHub organization ownership
  • Repository administrators
  • Branch protection
  • Pull requests
  • Code review
  • Commit history
  • Releases
  • Production branches
  • Archived repositories
  • Backup
  • Access removal after separation

Critical principle: No single developer should be the only person capable of accessing, understanding, deploying, or recovering a Kairos system.

Chapter 09

Cloud & Infrastructure Governance

Create a central register of:

  • Domains
  • DNS
  • Hosting
  • Vercel/cloud infrastructure
  • MongoDB/databases
  • Storage
  • Email infrastructure
  • APIs
  • Authentication systems
  • Third-party integrations
  • Monitoring systems

Each system should identify:

System → Owner → Administrator → Backup Administrator → Vendor → Billing Owner → Credentials Location → Production Environment → Backup/Recovery Method
Chapter 10

Credentials, Secrets & Access

Passwords and production credentials must never depend upon an individual's memory, personal email, or private password manager.

Govern

  • API keys
  • Database credentials
  • OAuth credentials
  • Cloud credentials
  • GitHub access
  • Domain registrar access
  • Production secrets
  • Encryption keys
  • AI-provider keys

Require

  • Company-controlled credential storage
  • MFA where available
  • Role-based access
  • Periodic access review
  • Immediate revocation when access is no longer required
  • Credential rotation after material personnel changes
Chapter 11

Software Development & Change Management

Define how software moves:

Idea → Requirement → Development → Review → Testing → Approval → Production → Monitoring

Not every change needs bureaucracy. The governance should be risk-based. Low-risk UI changes can move rapidly.

Changes requiring stronger review and testing

  • Patient information
  • Clinical calculations
  • Authentication
  • Permissions
  • Financial information
  • Production databases
  • Security
  • Regulatory workflows
Chapter 12

AI Governance

Kairos should establish this now rather than later.

AI systems must have defined

  • Purpose
  • Approved models/providers
  • Data-access boundaries
  • Human oversight
  • Logging
  • Validation expectations
  • Cost controls
  • Security requirements
  • PHI/PII restrictions
  • Model-change procedures

Fundamental rule: AI output is not automatically truth.

Where an AI system influences clinical, regulatory, financial, or other material decisions, appropriate verification and human oversight are required.

Chapter 13

Data Governance

Every important dataset should have:

  • Business owner
  • Technical owner
  • Source of truth
  • Access rules
  • Backup policy
  • Retention policy
  • Recovery procedure
  • Data-quality expectations

Production data should never exist solely on someone's laptop.

Chapter 14

Cybersecurity & Incident Management

Establish minimum requirements for:

  • MFA
  • Device security
  • Encryption
  • Access control
  • Backups
  • Logging
  • Vulnerability management
  • Security updates
  • Phishing
  • Lost devices
  • Credential compromise
  • Incident reporting

Employees must report suspected compromise immediately.

Do not investigate or quietly fix a significant security incident without notifying the appropriate company authority.

Part IV

Intellectual Property

Chapters 15–16
Chapter 15

Intellectual Property Ownership

Clearly govern:

  • Software
  • Algorithms
  • Documentation
  • Clinical technology
  • Processes
  • Designs
  • Databases
  • AI workflows
  • Training materials
  • Brands
  • Domain names
  • Inventions

IP ownership must be established contractually with employees, consultants, partners, and developers.

No ambiguity should exist about whether technology developed for Kairos belongs to an individual or to the company.

Chapter 16

Third-Party & Open-Source Technology

Maintain visibility into:

  • Open-source libraries
  • Commercial software
  • APIs
  • AI models
  • SaaS services
  • Cloud services
  • Third-party datasets

Licensing obligations must be respected.

Developers should not introduce technology carrying unacceptable licensing, security, privacy, or commercial restrictions.

Part V

Commercial Governance

Chapters 17–19
Chapter 17

Client & Business Development Governance

Client relationships are corporate relationships.

Maintain a corporate pipeline containing:

Lead → Contact → Opportunity → Proposal → Value → Probability → Owner → Next Action → Expected Close

No business opportunity should reside exclusively inside someone's personal contacts, inbox, or memory.

Chapter 18

Contracts & Commitments

Maintain a central contract register.

For every agreement:

Client → Agreement → Effective Date → Term → Financial Value → Kairos Obligations → Client Obligations → Renewal → Termination → Owner

Only authorized personnel may execute agreements.

Chapter 19

Vendor & Third-Party Governance

Before material vendors receive access to Kairos information or systems, establish:

  • Business purpose
  • Contract
  • Confidentiality
  • Data access
  • Security requirements
  • Financial terms
  • Responsible Kairos owner
  • Termination process

Vendor access must be removed when no longer required.

Part VI

Financial Governance

Chapters 20–21
Chapter 20

Financial Authority

Define authorization thresholds for:

  • Purchases
  • Contracts
  • Reimbursements
  • Hiring
  • Consulting
  • Technology
  • Travel
  • Vendor payments
  • Capital expenditure

No individual should simultaneously initiate, approve, and reconcile a material financial transaction where reasonable segregation is possible.

Chapter 21

Revenue, Billing & Collections

Every commercial engagement should connect:

Contract → Deliverable → Invoice → Payment → Outstanding Balance

Management should have visibility into:

  • Contract value
  • Amount invoiced
  • Amount collected
  • Outstanding receivables
  • Aging
  • Expected collections
Part VII

People & Accountability

Chapters 22–24
Chapter 22

Roles, Responsibilities & Accountability

Every significant role should have:

  • Defined responsibilities
  • Reporting relationship
  • Decision authority
  • Expected deliverables
  • Performance measures
  • Escalation responsibilities

Seniority does not eliminate accountability.

Chapter 23

Joining, Role Changes & Separation

Joining

Provision only required access.

Role Change

Review access when responsibilities change.

Separation — immediately address

  • Email
  • GitHub
  • Cloud
  • Databases
  • Credentials
  • Applications
  • Documents
  • Company equipment
  • Client relationships

Conduct a formal knowledge transfer before departure whenever possible.

Chapter 24

Business Continuity & Key-Person Risk

Kairos should be capable of continuing operations if any single individual becomes unexpectedly unavailable.

For every critical function:

Primary Owner → Backup Owner → Documentation → Credentials → Recovery Procedure

The company should never have to say:

“Only that person knows how this works.”
Part VIII

Management Operating System

Chapters 25–26
Chapter 25

Management Visibility

Leadership should have a concise view of:

BUSINESSPipeline • Contracts • Revenue • Collections
CLINICALActive Studies • Milestones • Risks • Escalations
TECHNOLOGYProduction Systems • Development • Incidents • Security
FINANCECash • Receivables • Payables • Commitments
PEOPLEResponsibilities • Deliverables • Issues

The purpose is visibility—not micromanagement.

Chapter 26

Decision & Escalation Framework

Every important matter should ultimately answer:

  • Who owns it?
  • Who decides?
  • Who needs to know?
  • Where is the decision recorded?
  • When must it be escalated?

If those five questions cannot be answered, governance is incomplete.

Part IX

The Kairos Standard

Kairos should remain entrepreneurial, fast, and innovative.

Corporate governance should not create bureaucracy for its own sake.

Its purpose is to ensure that the company can move quickly without becoming dependent upon individual people, undocumented decisions, inaccessible information, or uncontrolled systems.

Ownership without fiefdoms.
Autonomy with accountability.
Confidentiality without concealment.
Speed without recklessness.
Innovation with control.
Technology without key-person dependency.
Authority with transparency.
Problems escalated early—not discovered late.

And above all:

If Kairos owns the responsibility, Kairos must have the governance necessary to fulfill that responsibility.