Access and authentication
Authenticated access only
Application data is reachable only through an authenticated session or an API key you issue.
Row-level ownership
Database access policies scope every record to its owning account.
SSO and 2FA
Single sign-on and two-factor authentication are available for organisation accounts.
Role-based permissions
Roles are stored and evaluated server-side; permissions are not client-controlled.
API keys
Keys are stored hashed, scoped to your account, and can be revoked at any time.
Data handling
Hosting
EU-hosted processing options are available on request.
Encryption in transit
All traffic to Kynesis is served over HTTPS.
Retention and deletion
Retention windows are configurable, and deletion requests are honoured.
Audit logs
Administrative and evaluation activity is logged for review.
Subprocessors
AI model providers and infrastructure providers are used to deliver evaluations; the current list is available on request.
Privacy and shared responsibility
Kynesis is responsible for the security of the platform, its access controls, and the processing described above. You remain responsible for what you upload, who you grant access to, the retention settings you choose, and the lawful basis for processing the conversations you evaluate.
A data processing agreement is available on request. For privacy requests, data exports, deletion, or security disclosures, contact us and we will respond within one business day.