Trust
Security & Data Handling
Researchers hand us unpublished data. Enterprises hand us data rooms. This page states plainly what we do with it, what controls exist today, and what we have not yet earned the right to claim.
How your data is handled
We do not train on your data
Your inputs, uploaded files, results, and generated outputs are never used to train AI models — ours or anyone else's. This applies on every plan, including pay-as-you-go.
Encrypted in transit and at rest
Data moving between you and K-Dense is encrypted in transit, and data held on our infrastructure is encrypted at rest.
You own your outputs
You retain full ownership of everything a run produces — reports, figures, code, data, and any intellectual property in them. K-Dense claims no rights over your work.
You can delete sessions
Sessions can be deleted directly from the K-Dense Web interface. Deleting a session removes its associated session data from our servers.
Our current compliance position
K-Dense is not SOC 2 audited, and we do not claim SOC 2 or HIPAA certification. We would rather tell you that here than have you discover it during a security review. The controls described above are real and in place; an independent audit attesting to them is not yet done.
If your organization requires a completed SOC 2 report, a signed BAA, or a validated environment before you can adopt a new tool, talk to us early. For regulated work, the practical path today is a private cloud or on-premises deployment inside the environment your own quality and security teams already govern — your controls, your audit trail, your boundary.
We will update this page when that position changes, rather than quietly upgrading the language elsewhere on the site.
Where your data can run
Hosted cloud (default)
K-Dense Web runs on our managed cloud infrastructure. Runs execute in isolated environments, and the frontier models behind the agents are accessed through their providers' APIs.
Private cloud (Enterprise)
Deploy K-Dense inside your own AWS, GCP, or Azure environment, so data stays within your network boundary and your data-residency rules.
On-premises (Enterprise)
Install K-Dense in your own data center for strict data-sovereignty or air-gapped requirements.
Bring your own data access (Enterprise)
Rather than uploading proprietary datasets, connect K-Dense to a data interface you control, so the agent queries your data where it already lives.
Deployment options beyond the hosted cloud are part of K‑Dense Enterprise.
Documents and contact
Policies
- Privacy Policy — what we collect, why, and how long we keep it
- Terms of Use — the terms governing your use of K‑Dense
Security questions
Send security reviews, questionnaires, and vendor assessments to our team directly. We answer them ourselves rather than routing them through sales.
contact@k-dense.ai