Protect the knowledge without exposing the person.
KEPT is built to keep customer knowledge separated, restrict access, and maintain evidence of important security and data events.
Current controls
Workspace isolation
Customer information is scoped by workspace. Database row-level security and service authorization are designed to deny cross-workspace access by default.
Role-based access
Administrative actions and knowledge access depend on authenticated roles and explicit permissions. Knowledge-sharing grants are scoped to the people and workspace involved. Access decisions are made by the control plane, never by an AI model: the AI layer receives only minimized, already-authorized context for each request.
Private attachment storage
Uploaded files are stored in private object storage and retrieved through authorized service paths. Deleting an attachment is designed to queue its stored file for removal.
Protected service boundaries
The public web application communicates with dedicated control-plane and AI services. Secrets and provider credentials are held in managed deployment environments rather than shipped to the browser.
Auditing
KEPT is built to record important authorization, security, consent, deletion, and model-processing events to support investigation and accountability.
AI-provider controls
AI requests are routed through KEPT's model gateway and recorded in an operational ledger. KEPT does not use customer content to train generalized AI models. Provider retention and no-training terms are governed by KEPT's provider agreements and live account configuration.
Data deletion
KEPT builds audited deletion paths for captured partner data and private attachments. Some limited billing, audit, security, consent, or legal records may be retained when permitted or required.
Reporting a vulnerability
To report a suspected vulnerability or security issue, contact support@kept.solutions. Please do not include active credentials or customer data in the initial message. We acknowledge reports, keep the reporter informed while we investigate, and credit reporters who want credit once a fix ships.
We welcome good-faith security research. If you make a good-faith effort to respect user privacy, avoid disrupting the service, access only your own test data, and give us reasonable time to fix an issue before disclosing it, we will not pursue or support legal action against your research. This policy is also published at /.well-known/security.txt.