Where your documents go, and where they do not.
The answer for your compliance team, written by the people who built the system. The documents behind it are available on request.
In short
Everything runs in the European Union. Model calls go to EU endpoints only, and the request itself carries the instruction that the provider may neither store nor train on it. A request that cannot be served that way fails; it does not fall back to a US endpoint.
Nobody at Khumo can open your documents. When files are stored at all, they sit in an EU bucket under your organisation's prefix, and support works from logs and error data, never from your files.
Three ways to run Khumo
| Mode | Documents | Facts and outputs | Model calls |
|---|---|---|---|
| Stored in the EU (default) | EU object storage, your organisation's prefix, deleted on request | EU database, versioned, deleted on request | EU endpoints, zero retention |
| Nothing stored | Held in memory for the run only, never written to disk | Only what you download or explicitly confirm | EU endpoints, zero retention |
| Your own cloud (on request) | Your storage | Your database | Models in your own cloud account and region |
What we put in writing
- A data-processing agreement under the GDPR with retention and deletion periods
- A subprocessor list: hosting, database and storage, model routing and model providers, all in EU regions
- A description of the hosting setup and the model-provider controls
- Deletion on request, confirmed in writing, for documents, facts and outputs
- An audit log per organisation of who uploaded, ran, corrected or approved what, and when
Tenant separation
Buy-side and sell-side customers are separate organisations in the system. Members of an organisation see only its companies. Access for an outside reviewer to one company is an explicit grant, logged and revocable.