Data securityHome

Where your documents go, and where they do not.

The answer for your compliance team, written by the people who built the system. The documents behind it are available on request.

In short

Everything runs in the European Union. Model calls go to EU endpoints only, and the request itself carries the instruction that the provider may neither store nor train on it. A request that cannot be served that way fails; it does not fall back to a US endpoint.

Nobody at Khumo can open your documents. When files are stored at all, they sit in an EU bucket under your organisation's prefix, and support works from logs and error data, never from your files.

Three ways to run Khumo

ModeDocumentsFacts and outputsModel calls
Stored in the EU (default)EU object storage, your organisation's prefix, deleted on requestEU database, versioned, deleted on requestEU endpoints, zero retention
Nothing storedHeld in memory for the run only, never written to diskOnly what you download or explicitly confirmEU endpoints, zero retention
Your own cloud (on request)Your storageYour databaseModels in your own cloud account and region

What we put in writing

  • A data-processing agreement under the GDPR with retention and deletion periods
  • A subprocessor list: hosting, database and storage, model routing and model providers, all in EU regions
  • A description of the hosting setup and the model-provider controls
  • Deletion on request, confirmed in writing, for documents, facts and outputs
  • An audit log per organisation of who uploaded, ran, corrected or approved what, and when

Tenant separation

Buy-side and sell-side customers are separate organisations in the system. Members of an organisation see only its companies. Access for an outside reviewer to one company is an explicit grant, logged and revocable.

Request the security documentation

See it on your own documents.