security

Security your whole team can trust

Your work runs in your own Private Cloud, your credentials stay out of the AI model's reach, and your data is never used to train anyone's models. Kumo makes the safe path the default path, and tells you plainly what's shipped today and what's still on the way.

last reviewed June 23, 2026

SOC 2 complianceSOC 2in progress
CASA complianceCASAin progress
GDPR complianceGDPRcompliant
CCPA complianceCCPAcompliant

GDPR and CCPA compliant today. SOC 2 and CASA are in progress, and we won't claim a certification until it's real.

how it's built

Seven things we get right by default

isolation

Your own Private Cloud

Every Kumo workspace runs in its own Private Cloud with dedicated storage. Memory, files, repositories, and traces stay scoped to you. One company's agent can never see, reach, or be reached by another's.

secrets

Credentials stay out of the AI's reach

API keys and tokens are sealed with AES-256-GCM, injected only at the moment they're needed, and never placed in the model's prompt. That's the architecture, not just a policy.

your data

We never train on your data

We don't sell your content and never use it to train models. We run on major providers, including OpenAI and Anthropic, whose API terms prohibit training on what we send them.

access

Conservative access by default

Connected tools are read-only-safe with a per-integration allowlist. Private connections are used only on turns from the member who connected them, and you can revoke any source at any time.

egress watcher

Outbound request monitoring (rolling out)

We're rolling out a runtime watcher that monitors proxied outbound web requests and asks an egress judge to catch likely credential or company-data leaks. It runs on our own internal workspace first and is being extended to customer workspaces, so it may not yet be enabled for a given workspace. When enabled it runs in shadow (surfacing review questions in the agent workspace) before any blocking, and in enforce mode those requests are blocked. It depends on traffic honoring the runtime proxy, so we describe it as cooperative monitoring rather than an airtight firewall.

ingress

Only signed traffic becomes work

Slack and Stripe events are signature-verified with timestamp freshness windows and timing-safe checks. Duplicate deliveries are de-duplicated, so a retry never triggers a second agent run.

infrastructure

Hardened control plane

The web app is served over TLS, the backend runs on Fly.io behind bearer-token calls, Private Clouds run on Modal, and deploys are automated with narrowly scoped credentials.

our promises

What we always do, and what we never do

The clearest way to read a security model is to see where the hard lines are. Here are ours.

We always

Isolate every workspace in its own Private Cloud and encrypt your secrets at rest

Send only the context a task reasonably needs, to your runtime, your tools, and your model

Work to block likely credential, customer-data, source-code, internal-file, or confidential-data leaks for proxied outbound web requests, via the outbound watcher we're rolling out (enabled internally first; enforcement blocks, shadow flags)

Verify the source of every inbound event before it becomes work

Tell you exactly what's shipped today and what's still in progress

We never

Use your data to train our own or any third-party model

Sell your Slack messages or connected-tool content

Put your API keys or tokens into the AI model's prompt

Claim the outbound watcher is a network-forced exfiltration firewall before that hardening is shipped

Claim a certification we don't actually hold

questions

bring it to your security review

Built to pass the questions you'll be asked

Start with a free trial, or talk to us about a DPA and the controls your security team needs. Kumo is built to be handed straight to review.

Hire your Agentread the privacy policy