Korrali — User Manual
The AI Trust Workspace for B2B SaaS companies selling to enterprise.
Answer customer security, privacy, and AI questionnaires in minutes. Generate AI governance policy documents from your own knowledge base. Publish a public trust page that buyers can read before they ask. All in one workspace.
Version 1.0 · Last updated 2026-05-26
Table of contents
- What Korrali does
- The 10-minute loop
- Getting started
- Building your knowledge base
- Answering your first questionnaire
- The policy pack (Growth)
- Your public trust page (Growth)
- Free tools (no sign-up)
- Plans and billing
- What Korrali is and is not
- Help and support
1. What Korrali does
If you sell B2B SaaS to enterprise, you already know the pattern: every deal stalls on a security or AI questionnaire. Procurement sends a 100-question spreadsheet. Engineering pulls the CTO into Slack threads. Answers get pasted between docs, drift across deals, and somebody has to remember what was true six months ago.
Korrali replaces that with a single workspace:
- A company knowledge base. You enter facts about your stack, data handling, AI usage, and policies once. Korrali stores them with structure and history.
- A questionnaire engine. Paste in a questionnaire — any format. Korrali generates grounded answers, each marked with a confidence level and traceable to the knowledge-base facts it used.
- An AI governance policy pack (Growth plan and above). Korrali drafts six starter policy documents — AI Use Policy, Data Handling Policy, Vendor Management Policy, and so on — adapted to your knowledge base. You review and edit, not write from scratch.
- A public trust page (Growth plan and above). One link you can share with prospects. Enterprise buyers can read it before they send a questionnaire — often shortening the questionnaire itself.
The goal is straightforward: fewer hours per deal on questionnaires, faster enterprise sales cycles, no surprises when procurement asks "do you have an AI policy?"
2. The 10-minute loop
The full first-time loop — from signing in to having answered questions you can paste back to a customer — takes about ten minutes. The loop:
- Sign in with email or Google.
- Set up your organization — one form, your company name.
- Add knowledge-base facts — at minimum, your AI provider, where data is stored, how it's encrypted, your subprocessors. Five to ten facts is enough to start.
- Paste a real questionnaire. Korrali generates grounded answers with confidence ratings. Approve, edit, or regenerate per question. Export to PDF or DOCX.
After that loop, every subsequent questionnaire is faster because your knowledge base is doing the work.

The dashboard. Each card jumps you into one of the four core modules. The Quick Start panel walks new users through the loop above.
3. Getting started
3.1 Sign in
Open trust.korrali.com (or uat.korrali.com if you're a tester). You'll see the sign-in screen.

You have two options:
- Continue with Google. Single-click sign-in via Google OAuth. Recommended.
- Send magic link. Enter your work email and we send a one-time sign-in link valid for a few minutes. No password to remember.
If this is your first time, you'll be sent to onboarding after signing in. Returning users go straight to the dashboard.
3.2 Set up your organization
Brand-new users land on a one-field onboarding screen that asks for your organization name (for example, Acme AI). This is the workspace name that appears on your trust page, on exports, and in the app header. Click Continue and you're in.
You can add teammates later — every workspace supports multiple members, each with a role (Owner, Admin, Member). Membership management is on the roadmap; for the early cohort, ping us through support and we'll add seats manually.
3.3 The dashboard
The dashboard is the home base. Four big cards across the top take you into the core modules: Knowledge base, Questionnaires, Policy pack, Trust page. A row below them surfaces the Free tools and a Quick Start panel that walks you through the 10-minute loop until you've completed it once.
The header has a global nav: KB · Questionnaires · Policies · Trust · Tools · Billing · your account. Same nav on every page.
4. Building your knowledge base
The knowledge base is the foundation. Every answer Korrali generates, every policy section it drafts, and every entry on your trust page is grounded in the facts you enter here. The cleaner your KB, the better everything downstream gets.

4.1 The seven categories
Facts are organised into seven categories, each meant to mirror the questions enterprise procurement actually asks:
| Category | What goes here |
|---|---|
| AI Use | Which models and providers you use, your use cases, human oversight, training-data policies, evaluation |
| Data Handling | What data you collect, residency, encryption (at-rest and in-transit), retention, PII handling, classification |
| Infrastructure | Cloud, regions, key services (compute, database, cache, queue), network isolation, secrets management |
| Security Controls | Access control, monitoring, incident response, vulnerability management, backup and recovery |
| Policies | Acceptable use, privacy policy, vendor management, AUP — links and a short description |
| Vendors | Subprocessors and other third parties handling customer data; their SOC 2 status |
| Compliance | Frameworks you align with (SOC 2, GDPR, EU AI Act, HIPAA) — what's in place, what's in progress, what doesn't apply |
The order matters: AI Use and Data Handling get asked first in almost every questionnaire, so start there. Compliance can come last.
4.2 Adding a fact
A fact is a short structured note:
- Category — pick from the seven above.
- Key — a slug like
encryption-at-restorprimary-llm-provider. Lowercase, hyphenated. Korrali uses this to deduplicate and link related answers. - Value — the answer itself. One to three sentences. Be specific: "AES-256 for PostgreSQL via AWS EBS. Backups encrypted, retained 30 days" beats "we use encryption".
- Source (optional) — a URL or document reference. Useful when an auditor or a CISO wants to verify.

4.3 Editing and history
Click into any existing fact to edit it. Every edit is recorded in history — you can see the previous ten versions of any fact, who edited it, and when. That matters when an answer in a past questionnaire references a fact that has since changed.
Tip. Don't try to fill the whole KB on day one. Add the ten facts that come up in your most recent questionnaire. The next questionnaire will surface five more gaps. After three or four questionnaires, your KB is broad enough to answer most of what comes in cold.
5. Answering your first questionnaire
This is the core flow.
5.1 Create a new questionnaire
From the dashboard or the Questionnaires tab, click New questionnaire.

You'll see a single form with two fields:
- Name. Something like "Acme Co — Security Review Q2 2026". This is just for your own tracking.
- Questions. Paste the questionnaire. Korrali accepts any format: one question per line, a numbered list, paragraphs separated by blank lines, the contents of a Word doc, a copy-paste from a Google Form. Korrali parses each individual question out automatically.

Click Create. Korrali parses the input and lands you on the questionnaire's detail page, with each question listed but no answers yet.
5.2 Generate answers
On the detail page, click Generate answers. Korrali walks through every question, consults your knowledge base, and produces a grounded answer for each.

Each answer is tagged with one of four states:
| Badge | What it means |
|---|---|
| High confidence (green) | The KB contained direct facts that answered the question. Answer should need light review at most. |
| Medium confidence (amber) | The KB had related but partial information. Korrali drew an inference. Worth reading carefully. |
| Low confidence (red) | The KB had little to go on. Korrali drafted a reasonable starting point but you should rewrite or fill in missing facts. |
| Missing data (red) | The KB was missing the relevant category entirely. Add facts and regenerate. |
You can regenerate any single question after adding KB facts, without re-running the whole questionnaire.
5.3 Approving and editing
Click any answer to edit it inline. When you're happy with it, mark it Approved. Approved answers feed your answer library — Korrali learns your phrasing and reuses approved answers in future questionnaires that ask similar questions.
Quality habit. Treat Low and Missing data answers as KB gaps, not Korrali failures. Add the missing fact, regenerate that one answer, and your KB is better for next time. After three or four questionnaires you'll rarely see Missing data anymore.
5.4 Exporting
Once you've reviewed answers, click Export. Korrali produces a clean PDF or DOCX file with the customer's questions on the left and your answers on the right — formatted to paste into a procurement portal, attach to an email, or upload to a vendor-management system.
6. The policy pack (Growth)
The policy pack turns your knowledge base into six starter governance documents. Available on the Growth plan and the Founding plan.

The six documents:
- AI Use Policy — what AI systems you operate, how, and the human oversight model.
- Data Handling Policy — what data you collect, where it lives, how long you keep it.
- Information Security Policy — encryption, access control, monitoring, incident response.
- Vendor Management Policy — how you vet, contract with, and review subprocessors.
- Acceptable Use Policy — what customers can and can't do with your service.
- Privacy Policy template — GDPR/CCPA-aware starting point for your public privacy page.
Each document is generated from your KB and adapted to your stack — if your KB says AWS us-east-1, the Information Security Policy references AWS; if it says GCP, the policy references GCP. Each section can be edited and approved independently, the same way questionnaire answers work.
When you export the pack, you get six PDF or DOCX files — ready to send to an enterprise buyer asking "Do you have a documented AI governance policy?"
Important. These are starter documents. Korrali generates a defensible baseline; we do not guarantee they meet any specific regulation or audit framework. Run them past legal before you treat them as your final position. See Section 10.
7. Your public trust page (Growth)
A trust page is a single public URL where prospects can read about your security, AI, and data practices — before they ask. Many enterprise buyers do this diligence pass before sending a questionnaire. A good trust page can replace half the questions on the questionnaire that follows.
Available on the Growth plan and the Founding plan.
7.1 What lives on the trust page
Sections you control:
- Overview. One short paragraph describing what your company does and your trust posture.
- AI usage. Adapted from your AI Use facts: providers, use cases, human oversight, training-data position.
- Data handling. Where data lives, encryption, retention.
- Security controls. Access, monitoring, incident response.
- Subprocessors. Your vendor list — Korrali pulls this from your Vendors category.
- Compliance. What's in place (SOC 2, GDPR alignment) and what's in progress.
- Contact. A security contact email and (optional) a PGP key.

7.2 Editing sections
Each section is editable. Korrali drafts the initial content from your KB; you refine. You can also add custom sections — for example, a Subprocessors changelog or an AI incidents disclosure. Same approve-per-section pattern as policies and questionnaires.
7.3 Publishing
When you click Publish, your trust page becomes available at:
https://trust.korrali.com/t/{your-org-slug}
(For example, https://trust.korrali.com/t/acme-ai.) The page is fully public — no login required. You can unpublish at any time with one click. Every publish updates a Last updated date at the top, so visitors know how fresh the information is.

Disclosure language. Every Korrali trust page carries a standard disclaimer at the bottom: "This page is provided by {your company} and has not been independently verified." This is intentional — see Section 10.
8. Free tools (no sign-up)
Korrali ships four standalone tools that don't require a paid plan. They live under the Tools tab. Each takes a minute or two and produces something useful — they're a fast way to evaluate Korrali before committing to a subscription, and they're useful in their own right.

- Security Questionnaire Analyzer. Paste a questionnaire, get back a categorised breakdown (security / privacy / AI / governance / vendor), an estimated time-to-answer, and the questions most likely to require missing internal info.
- AI Vendor Risk Scanner. Tell us about an AI vendor you're considering; we produce a short risk profile covering data handling, training-data position, residency, and contract red-flags to ask about.
- EU AI Act Readiness Checker. Answer a short set of questions about your product; we tell you which EU AI Act risk class likely applies (Minimal / Limited / High / Prohibited) and what obligations follow.
- Security Policy Generator. Pick a policy type, tell us about your company size, industry, and cloud; we draft a starter policy you can paste into your handbook.

All four tools are free and unlimited for signed-in users.
9. Plans and billing
Korrali has four plans. All plans bill monthly via Stripe. Founding is a limited offer (first 50 spots) at Growth features lifetime-locked at $299/mo.

| Founding (first 50, lifetime) | Pro | Growth | |
|---|---|---|---|
| Price | $299/mo | $199/mo | $499/mo (annual — contact us) |
| Knowledge base | ✓ | ✓ | ✓ |
| Questionnaire engine | ✓ | ✓ | ✓ |
| Answer library | ✓ | ✓ | ✓ |
| Free tools | ✓ | ✓ | ✓ |
| Policy pack (6 docs) | ✓ | — | ✓ |
| Public trust page | ✓ | — | ✓ |
| Founder onboarding | ✓ | — | — |
| Priority support + SLA | ✓ | — | ✓ |
9.1 Starting a paid plan
From the Billing page, click Start Pro or Start Growth. Stripe's checkout opens — you complete payment and are redirected back to Korrali. The subscription activates within seconds.
To claim a Founding seat, click Claim founding seat (visible while spots remain). Founding gets Growth features at $299/mo, locked forever.
9.2 Upgrading and downgrading
You can upgrade from Pro to Growth in one click at any time — pro-rated automatically. Downgrades take effect at the end of the current billing period. If you cancel, you keep access until the period ends; your data stays for 30 days after that in case you reactivate.
9.3 Annual and custom contracts
Growth annual is available founder-to-founder. Book a call from the Billing page. Custom DPAs, security reviews, and SLA addenda also go through the same channel.
10. What Korrali is and is not
Korrali is a productivity workspace. It is not a regulator, an auditor, or a law firm. Reading this section carefully will save you trouble.
What Korrali is
- A workspace for answering questionnaires faster.
- A drafting tool that produces a defensible baseline for policy documents from your own knowledge base.
- A publishing tool for a self-attested trust page.
What Korrali is not
- Not a certification. Korrali does not certify, accredit, audit, or attest to anything. Generating a policy pack does not make you SOC 2 compliant. Publishing a trust page does not make you GDPR compliant. Compliance is determined by qualified auditors against actual practice — not by documents.
- Not legal advice. Generated policies are templates and starting points. They are not legal advice. Run them past counsel before relying on them in a contract, with a regulator, or in a dispute.
- Not independent verification. Anything on your trust page is provided by you. Korrali does not verify your claims. The standard disclaimer on every trust page makes this explicit. Buyers reading the page should understand they are reading self-attested information.
- Not a replacement for human review. Every Korrali-generated answer should be reviewed by a human before it goes to a customer. The confidence levels are heuristics, not guarantees. Approving an answer in Korrali means you are taking responsibility for it.
Language Korrali deliberately avoids
You will not find Korrali using words like compliant, certified, audit-ready, or guaranteed compliance in your generated documents or trust page. Instead you'll see privacy commitments, designed for, supports your, as a starting point. This is deliberate — it keeps the language honest and keeps you out of trouble with regulators who care a lot about precise claims.
11. Help and support
- Support email. support@korrali.com — for technical issues, billing, or account changes.
- Founder support. Founding members get founder onboarding plus direct access. Other plans can book a 30-minute call for custom questions, demos, or annual contract discussions.
- Security contact. security@korrali.com — for responsible disclosure of vulnerabilities.
- Marketing site. korrali.com — pricing, sample output, blog.
- Trust page. korrali.com/trust.html — Korrali's own trust page.
Korrali is built by a small team in Bangalore and Singapore. We read every support email ourselves.