Kumo is built with privacy and security as first-order design constraints, not a checkbox project we run before each big deal. This page is an honest summary of what's live today, what's in progress, and what we'll happily put in writing.
We follow GDPR by design. DPA available on request.
Currently in observation window with our auditor.
Will follow Type I; 12-month observation thereafter.
Summary report available under NDA on request.
Everything below is live for every customer on every plan. We'll happily walk through any of it on a call, share architecture diagrams under NDA, or take a security questionnaire.
Data is encrypted at rest and in transit, end-to-end, across the platform.
Strong auth by default, with enterprise options on higher plans.
Role-based access control down to the field, with sensitive-action approvals.
Every action, every API call, every approval is logged immutably.
Choose where your tenant lives, and we keep it there.
Customer data is isolated at the application and storage layer.
Multi-region backups and tested restores, not just nightly snapshots.
External pen-tests, internal scanning, and a dedicated security on-call.
Public status page, real incident comms, sensible targets.
Kumo AI is the most-asked-about part of our security posture. The short version: your data stays yours, the model only sees what your asking user is allowed to see, and every AI action is logged and reversible.
Your prompts and your data are used to answer your queries, full stop. They are not used to train Kumo's models or any third-party model.
The AI retrieves only records the asking user is allowed to see, evaluated against the same RBAC layer as the rest of the platform.
Every AI answer cites the records it pulled. Every AI action explains its reasoning in plain language and surfaces what it changed.
Any AI action can be rolled back in one click. Critical actions (pay changes, terminations) always require explicit human approval.
A current, honest list of every vendor we use to deliver Kumo. We'll notify you in writing before adding any new subprocessor that processes customer data.
Last updated 26 May 2026. Want the change-log? Ask security@kumohr.com to add you to the subprocessor notification list.
We treat security researchers as collaborators. If you've found a vulnerability, please report it via the channels below. We respond within one business day and won't take legal action for good-faith research.
We accept reports via PGP-encrypted email or our HackerOne program. We'll acknowledge receipt within one business day, triage within three, and tell you what we're doing about it within ten. Hall-of-fame credit for valid reports; bounties for impactful ones.
Pen-test summaries, architecture diagrams, security questionnaire responses, all available on request.