Security at Kelu

We take security seriously. Learn about our practices, certifications, and how we protect your data.

Compliance & Certifications

SOC 2 Type II

Annual audit of security controls

Certified
GDPR

EU data protection compliance

Compliant
CCPA

California privacy compliance

Compliant
ISO 27001

Information security management

In Progress

Security Features

Encryption

All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption.

Access Control

Role-based access control (RBAC) with principle of least privilege. SSO via OIDC and SAML 2.0. MFA required for all employees.

Infrastructure

Hosted on AWS with SOC 2 certified data centers. Geographic redundancy and automatic failover.

Monitoring

24/7 security monitoring, intrusion detection, and automated alerting for anomalies.

Penetration Testing

Annual third-party penetration tests and continuous vulnerability scanning.

Incident Response

Documented incident response plan with defined escalation procedures and SLAs.

No Training on Customer Data

Kelu never uses your documents, questions, or answers to train AI models. Your knowledge base is used solely to answer your users' questions.

PII Masking

Automatic detection and masking of phone numbers, names, emails, credit card numbers, IBANs, and IP addresses before content is stored or sent to any LLM. Custom regex patterns configurable per workspace.

Data Retention Controls

Per-workspace data retention policies: set a rolling retention window (e.g. 30/90/365 days) or choose zero-data-retention mode where no conversation data is persisted beyond the active session.

Security Practices

Secure Development

  • Secure SDLC with security reviews
  • Automated security testing in CI/CD
  • Dependency vulnerability scanning
  • Code review requirements

Employee Security

  • Background checks for all employees
  • Security awareness training
  • Confidentiality agreements
  • Access deprovisioning procedures

Data Protection

  • No training on customer data — ever
  • PII masking before LLM and storage (phone, email, CC, IBAN, IP, names)
  • Custom PII regex patterns per workspace
  • Zero-data-retention option available
  • Per-workspace configurable retention windows
  • Backup, recovery, and secure data disposal procedures

Identity & Access

  • SSO via OIDC (Google, GitHub, custom IdP)
  • SAML 2.0 for enterprise identity providers
  • Role-based access: owner, member, user
  • Per-knowledge-base chat permissions
  • Access deprovisioning on member removal
  • Audit logs for all sensitive workspace actions

Responsible Disclosure

We welcome security researchers to report vulnerabilities responsibly. Please email security issues to our security team.

Report security vulnerabilities to:

[email protected]

Please include detailed steps to reproduce the issue. We aim to respond within 24 hours.

Questions about security?

Our security team is happy to answer questions and provide additional documentation.

Contact Security Team