security
Security your whole team can trust
Your work runs in your own Private Cloud, your credentials stay out of the AI model's reach, and your data is never used to train anyone's models. Kumo makes the safe path the default path, and tells you plainly what's shipped today and what's still on the way.
last reviewed June 23, 2026
SOC 2in progress
CASAin progress
GDPRcompliantGDPR and CCPA compliant today. SOC 2 and CASA are in progress, and we won't claim a certification until it's real.
how it's built
Seven things we get right by default
isolation
Your own Private Cloud
Every Kumo workspace runs in its own Private Cloud with dedicated storage. Memory, files, repositories, and traces stay scoped to you. One company's agent can never see, reach, or be reached by another's.
secrets
Credentials stay out of the AI's reach
API keys and tokens are sealed with AES-256-GCM, injected only at the moment they're needed, and never placed in the model's prompt. That's the architecture, not just a policy.
your data
We never train on your data
We don't sell your content and never use it to train models. We run on major providers, including OpenAI and Anthropic, whose API terms prohibit training on what we send them.
access
Conservative access by default
Connected tools are read-only-safe with a per-integration allowlist. Private connections are used only on turns from the member who connected them, and you can revoke any source at any time.
egress watcher
Outbound request monitoring (rolling out)
We're rolling out a runtime watcher that monitors proxied outbound web requests and asks an egress judge to catch likely credential or company-data leaks. It runs on our own internal workspace first and is being extended to customer workspaces, so it may not yet be enabled for a given workspace. When enabled it runs in shadow (surfacing review questions in the agent workspace) before any blocking, and in enforce mode those requests are blocked. It depends on traffic honoring the runtime proxy, so we describe it as cooperative monitoring rather than an airtight firewall.
ingress
Only signed traffic becomes work
Slack and Stripe events are signature-verified with timestamp freshness windows and timing-safe checks. Duplicate deliveries are de-duplicated, so a retry never triggers a second agent run.
infrastructure
Hardened control plane
The web app is served over TLS, the backend runs on Fly.io behind bearer-token calls, Private Clouds run on Modal, and deploys are automated with narrowly scoped credentials.
our promises
What we always do, and what we never do
The clearest way to read a security model is to see where the hard lines are. Here are ours.
We always
Isolate every workspace in its own Private Cloud and encrypt your secrets at rest
Send only the context a task reasonably needs, to your runtime, your tools, and your model
Work to block likely credential, customer-data, source-code, internal-file, or confidential-data leaks for proxied outbound web requests, via the outbound watcher we're rolling out (enabled internally first; enforcement blocks, shadow flags)
Verify the source of every inbound event before it becomes work
Tell you exactly what's shipped today and what's still in progress
We never
Use your data to train our own or any third-party model
Sell your Slack messages or connected-tool content
Put your API keys or tokens into the AI model's prompt
Claim the outbound watcher is a network-forced exfiltration firewall before that hardening is shipped
Claim a certification we don't actually hold
questions
bring it to your security review
Built to pass the questions you'll be asked
Start with a free trial, or talk to us about a DPA and the controls your security team needs. Kumo is built to be handed straight to review.
Hire your Agentread the privacy policy