> ## Documentation Index
> Fetch the complete documentation index at: https://docs.keldyn.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and privacy

> How Keldyn protects customer data and AI-assisted governance workflows.

This page summarizes how the Keldyn platform handles security and privacy for customer tenants. It is intended for customers, prospects, and compliance reviewers.

## Platform posture

* Customer data is stored and processed in professionally managed cloud infrastructure.
* Traffic to Keldyn services uses HTTPS.
* Production and non-production environments are separated.

For vendor questionnaires or deeper technical assurance, contact your Keldyn representative or use the materials in your published Trust Center. Detailed hosting and defensive-stack information is shared under appropriate confidentiality, not in public docs.

## Authentication and access control

* Users sign in with authenticated sessions; SSO is available where configured.
* Optional multi-factor authentication.
* Team roles and permissions control who can see and change governance data.
* Machine and AI-agent clients authenticate separately from interactive users.
* Trust Center gated resources use access grants; published Trust Center content is intentionally public.

## Data protection

* Data is encrypted in transit and at rest.
* Integration credentials are stored encrypted.
* Passwords are hashed; platform secrets are not exposed to end users.

## AI data handling

Keldyn uses generative AI for governance workflows (for example questionnaires, architecture assistance, control suggestions, and document help).

| Property               | Practice                                                                               |
| ---------------------- | -------------------------------------------------------------------------------------- |
| Model ownership        | Inference-only — Keldyn does not train or fine-tune models on your data                |
| Human oversight        | AI suggestions do not overwrite accepted or human-authored control findings by default |
| Access to AI artifacts | Same team and use-case authorization as other confidential governance data             |

Prompts may include confidential governance content. Treat AI prompts and outputs as confidential business data under your organization’s policies.

## Logging and auditability

Significant use-case and organization actions are recorded in audit trails suitable for compliance review. Access to personal data is logged for accountability.

## Reporting a security issue

Found a suspected vulnerability or an active security incident? See [Report a bug or security issue](/report-a-problem) for the address to use and how fast we respond.

## Knowledgebase

Indexed organisational documents follow the same encryption and team isolation as the rest of the product, with extra collection limits: you choose a folder, space, page set, or channel; connectors are read-only; Otter audio is never fetched. Source-side sharing does not carry over — anyone who can open Knowledgebase can read what you connected. See [Knowledgebase privacy](/knowledgebase-privacy).

## Related

* [Knowledgebase privacy](/knowledgebase-privacy)
* [Data security](/data-security)
* [Data flow](/data-flow)
* [Cybersecurity](/cybersecurity)
* [Report a bug or security issue](/report-a-problem)
* [Compliance](/compliance)
* [API compliance documentation](/api-compliance)
* [Frameworks & controls](/frameworks-and-controls)
* [Evidence & audits](/evidence-and-audits)
