Trust

    Security and data protection at Kynesis

    This page is maintained by the Kynesis team to answer common security and privacy questions about the platform. It describes our current practices and available controls — it is not an independent certification or audit report.

    Access and authentication

    Authenticated access only

    Application data is reachable only through an authenticated session or an API key you issue.

    Row-level ownership

    Database access policies scope every record to its owning account.

    SSO and 2FA

    Single sign-on and two-factor authentication are available for organisation accounts.

    Role-based permissions

    Roles are stored and evaluated server-side; permissions are not client-controlled.

    API keys

    Keys are stored hashed, scoped to your account, and can be revoked at any time.

    Data handling

    Hosting

    EU-hosted processing options are available on request.

    Encryption in transit

    All traffic to Kynesis is served over HTTPS.

    Retention and deletion

    Retention windows are configurable, and deletion requests are honoured.

    Audit logs

    Administrative and evaluation activity is logged for review.

    Subprocessors

    AI model providers and infrastructure providers are used to deliver evaluations; the current list is available on request.

    Privacy and shared responsibility

    Kynesis is responsible for the security of the platform, its access controls, and the processing described above. You remain responsible for what you upload, who you grant access to, the retention settings you choose, and the lawful basis for processing the conversations you evaluate.

    A data processing agreement is available on request. For privacy requests, data exports, deletion, or security disclosures, contact us and we will respond within one business day.

    See what Kynesis can uncover in your customer interactions and AI systems.