Skip to main content
This page summarizes how the Keldyn platform handles security and privacy for customer tenants. It is intended for customers, prospects, and compliance reviewers.

Platform posture

  • Customer data is stored and processed in professionally managed cloud infrastructure.
  • Traffic to Keldyn services uses HTTPS.
  • Production and non-production environments are separated.
For vendor questionnaires or deeper technical assurance, contact your Keldyn representative or use the materials in your published Trust Center. Detailed hosting and defensive-stack information is shared under appropriate confidentiality, not in public docs.

Authentication and access control

  • Users sign in with authenticated sessions; SSO is available where configured.
  • Optional multi-factor authentication.
  • Team roles and permissions control who can see and change governance data.
  • Machine and AI-agent clients authenticate separately from interactive users.
  • Trust Center gated resources use access grants; published Trust Center content is intentionally public.

Data protection

  • Data is encrypted in transit and at rest.
  • Integration credentials are stored encrypted.
  • Passwords are hashed; platform secrets are not exposed to end users.

AI data handling

Keldyn uses generative AI for governance workflows (for example questionnaires, architecture assistance, control suggestions, and document help). Prompts may include confidential governance content. Treat AI prompts and outputs as confidential business data under your organization’s policies.

Logging and auditability

Significant use-case and organization actions are recorded in audit trails suitable for compliance review. Access to personal data is logged for accountability.

Reporting a security issue

Found a suspected vulnerability or an active security incident? See Report a bug or security issue for the address to use and how fast we respond.

Knowledgebase

Indexed organisational documents follow the same encryption and team isolation as the rest of the product, with extra collection limits: you choose a folder, space, page set, or channel; connectors are read-only; Otter audio is never fetched. Source-side sharing does not carry over — anyone who can open Knowledgebase can read what you connected. See Knowledgebase privacy.