Security at KEPT

Protect the knowledge without exposing the person.

KEPT is built to keep customer knowledge separated, restrict access, and maintain evidence of important security and data events.

Last updated: August 24, 2026

Current controls

Workspace isolation

Customer information is scoped by workspace. Database row-level security and service authorization are designed to deny cross-workspace access by default.

Role-based access

Administrative actions and knowledge access depend on authenticated roles and explicit permissions. Knowledge-sharing grants are scoped to the people and workspace involved. Access decisions are made by the control plane, never by an AI model: the AI layer receives only minimized, already-authorized context for each request.

Private attachment storage

Uploaded files are stored in private object storage and retrieved through authorized service paths. Deleting an attachment is designed to queue its stored file for removal.

Protected service boundaries

The public web application communicates with dedicated control-plane and AI services. Secrets and provider credentials are held in managed deployment environments rather than shipped to the browser.

Auditing

KEPT is built to record important authorization, security, consent, deletion, and model-processing events to support investigation and accountability.

AI-provider controls

AI requests are routed through KEPT's model gateway and recorded in an operational ledger. KEPT does not use customer content to train generalized AI models. Provider retention and no-training terms are governed by KEPT's provider agreements and live account configuration.

Data deletion

KEPT builds audited deletion paths for captured partner data and private attachments. Some limited billing, audit, security, consent, or legal records may be retained when permitted or required.

Shared responsibility

Customers are responsible for choosing appropriate participants, providing required workplace notices, configuring access, protecting administrator accounts, and avoiding prohibited or regulated data.

Reporting a vulnerability

To report a suspected vulnerability or security issue, contact support@kept.solutions. Please do not include active credentials or customer data in the initial message. We acknowledge reports, keep the reporter informed while we investigate, and credit reporters who want credit once a fix ships.

We welcome good-faith security research. If you make a good-faith effort to respect user privacy, avoid disrupting the service, access only your own test data, and give us reasonable time to fix an issue before disclosing it, we will not pursue or support legal action against your research. This policy is also published at /.well-known/security.txt.