How we protect your data
We only publish controls that already work. Every claim below explains how it works, and the documents behind it are one click away.
Documents
- Data Processing AgreementRoles, scope, breach notice, deletion
- SubprocessorsWho processes data, for what, and where
- Security modelIdentity, isolation, guards, audit
- Responsible disclosureHow to report a vulnerability
- Privacy noticeWhat this site and the product collect
- Terms of serviceThe agreement for using Kirky
Your API credentials never reach our servers
How it works
When someone asks about live data, Kirky doesn’t call your systems. Their browser does: the widget calls your own read endpoints with that person’s existing session, the same way your app already does.
Kirky receives the question, the screen the person is on and only the response fields your admin selected. Your API keys, cookies and tokens stay in your app.
Proof
View as text
- The user’s browser sends the question and the screen context to the Kirky API.
- When the answer needs live data, Kirky asks the browser to call your API. The browser calls it with the user’s own session; your credentials never pass through us.
- The browser returns only the response fields your admin selected, and Kirky answers from them.
- Optional on Scale: a read-only database connector runs in your network and connects out to Kirky. We never open a port into your network.
Your data doesn’t train models
How it works
Your documents, questions and answers are used to serve your workspace and nothing else. That’s written into the Data Processing Agreement you sign.
The model provider is configured not to retain requests, and invocation logs stay in our own storage.
Proof
Customer data is not used to train or improve any model.
What we keep, and for how long
| Data | Kept for |
|---|---|
| Conversations | 90 days by default; your admin can shorten it |
| Audit log | 13 months |
| Rows read from your API or database | Not stored; used for the answer and discarded |
| Documents you upload | Until you delete them |
| Centinela profiles | Pseudonymized; personal fields are hashed per workspace |
Data and processing in the United States
How it works
Storage, search and the AI models all run in the United States. Model calls use a United States inference profile, so a request is never processed elsewhere.
The subprocessors page lists every company that processes data for us, what it does and where.
Proof
Every document answer cites its source
How it works
Answers from your documents run in strict mode: every statement has to carry a quote from the passage it came from.
Before the answer is shown, each quote is compared word for word with that passage in code. A quote that doesn’t match is removed, and if nothing is left Kirky says it doesn’t know.
Proof
“Damaged goods may be returned within 15 calendar days of delivery, with the delivery note.”
Actions ask for confirmation and never delete
How it works
Kirky can create or update records only through the write endpoints your admin registers, and only POST, PUT and PATCH. Delete isn’t an operation it has.
Every change shows a preview first. Nothing happens until the person confirms it, and the change runs with their own session.
Proof
- Preview
- Person confirms
- Saved with their session
The rest of the model
The same rules hold in every workspace, from the first day.
Permissions
Roles come from the token your backend signs. A new role starts with no permissions until your admin grants them, and Kirky only offers the tools and documents that role is allowed to use.
Encryption
Everything travels over TLS. Data at rest is encrypted with keys scoped to your workspace; Enterprise can use a dedicated key or its own.
Workspace isolation
Your workspace ID comes only from our signed session, never from what a request claims. Storage and search are partitioned per workspace, and an isolation test suite blocks every deploy that fails it.
Staff access
Our team can only act inside your workspace through a support session that is time-limited, requires multi-factor sign-in and shows up in your audit log.
Audit log
Sign-ins, questions, actions, configuration changes and support sessions are recorded in an audit log your admin can review and export.
Centinela
Centinela learns from your history without keeping personal data in clear: names and emails are pseudonymized with a key unique to your workspace. It warns; it never blocks.
How to evaluate us
Read the DPA, the subprocessor list and the security model. If you need anything else for your review, write to security@kirkyapp.com.