Skip to main content

Trust

Security & Data Handling

Researchers hand us unpublished data. Enterprises hand us data rooms. This page states plainly what we do with it, what controls exist today, and what we have not yet earned the right to claim.

How your data is handled

We do not train on your data

Your inputs, uploaded files, results, and generated outputs are never used to train AI models — ours or anyone else's. This applies on every plan, including pay-as-you-go.

Encrypted in transit and at rest

Data moving between you and K-Dense is encrypted in transit, and data held on our infrastructure is encrypted at rest.

You own your outputs

You retain full ownership of everything a run produces — reports, figures, code, data, and any intellectual property in them. K-Dense claims no rights over your work.

You can delete sessions

Sessions can be deleted directly from the K-Dense Web interface. Deleting a session removes its associated session data from our servers.

Our current compliance position

K-Dense is not SOC 2 audited, and we do not claim SOC 2 or HIPAA certification. We would rather tell you that here than have you discover it during a security review. The controls described above are real and in place; an independent audit attesting to them is not yet done.

If your organization requires a completed SOC 2 report, a signed BAA, or a validated environment before you can adopt a new tool, talk to us early. For regulated work, the practical path today is a private cloud or on-premises deployment inside the environment your own quality and security teams already govern — your controls, your audit trail, your boundary.

We will update this page when that position changes, rather than quietly upgrading the language elsewhere on the site.

Where your data can run

Hosted cloud (default)

K-Dense Web runs on our managed cloud infrastructure. Runs execute in isolated environments, and the frontier models behind the agents are accessed through their providers' APIs.

Private cloud (Enterprise)

Deploy K-Dense inside your own AWS, GCP, or Azure environment, so data stays within your network boundary and your data-residency rules.

On-premises (Enterprise)

Install K-Dense in your own data center for strict data-sovereignty or air-gapped requirements.

Bring your own data access (Enterprise)

Rather than uploading proprietary datasets, connect K-Dense to a data interface you control, so the agent queries your data where it already lives.

Deployment options beyond the hosted cloud are part of K‑Dense Enterprise.

Documents and contact

Policies

Security questions

Send security reviews, questionnaires, and vendor assessments to our team directly. We answer them ourselves rather than routing them through sales.

contact@k-dense.ai