Security & Data Protection
Your company's knowledge should stay your company's knowledge.
KeyPersonAI has a working private portal for controlled pilots and reference implementations. It uses encrypted connections, passwordless sign-in, organization-scoped access, and private cloud storage. We distinguish controls that exist today from higher-assurance options that require additional scoping.
Last updated August 2026. We update this page as the architecture evolves, and we do not claim controls or certifications that are not yet in place.
Foundation
Built on infrastructure that already meets enterprise security standards.
The website and portal run on Cloudflare. Selected AI and email services process only the data needed for their functions. A vendor's certification supports the overall security model, but it does not make KeyPersonAI itself certified.
Cloudflare
Hosting & edge infrastructure
SOC 2 Type II, ISO 27001, ISO 27018, PCI DSS Level 1. HIPAA-eligible services available for engagements that require a Business Associate Agreement.
Anthropic Claude
AI processing
Commercial API processing. Anthropic states that commercial inputs and outputs are not used to train its models by default and that standard API inputs and outputs are deleted from its backend within 30 days, subject to stated safety, legal, and contract exceptions. Stricter retention requires separate approval.
Resend
Transactional email
Used for transactional messages such as sign-in links and demo-request delivery. Sensitive interview content is not intentionally placed in routine email.
Current Portal Controls
Practical protection without pretending the system is staff-blind.
Authorized KeyPersonAI administrators and contracted cloud providers can technically access stored material when necessary to operate, secure, troubleshoot, or support the service. We do not currently claim end-to-end encryption, customer-held keys, HIPAA compliance, or attorney-client privilege protection.
Encryption in transit
Portal traffic uses HTTPS with modern TLS so recordings, documents, and responses are encrypted while moving between the customer's device and the service.
Encryption at rest
The cloud platform encrypts stored database records and uploaded objects at rest. Customer-held or per-project encryption keys are not part of the current baseline service.
Tenant isolation
Portal queries and files are scoped by organization so an authenticated customer cannot search, retrieve, or access another customer's material.
Limited administrative access
Administrative access is intended for operation, security, quality review, and authorized support. A staff-blind or customer-key-controlled deployment requires separate architecture and contract terms.
Customer-controlled access
Access is assigned to registered users within an organization. Project-level and sensitive-topic restrictions should be confirmed during scoping because they are not uniformly available in every workflow.
Review before publishing
Review and approval are part of the engagement process. The exact approval workflow is agreed before a knowledge base is released to successors or a broader team.
Security logging
The service records selected operational events. A customer-visible, comprehensive audit trail is not yet claimed as a baseline feature.
Limited retention
An authorized customer can delete original interview audio from the portal after transcription while preserving the transcript. Uploaded source files can also be removed. Other retention and deletion expectations are set in the engagement terms.
Commercial AI terms
The portal currently uses commercial services from Anthropic, Cloudflare, and OpenAI for different AI functions. Provider terms and configuration are reviewed before sensitive engagements.
Export and deletion
Ownership, export, retention, deletion, and service-provider processing are defined in the engagement agreement rather than implied by website copy.
Future Higher-Confidentiality Option
Customer-controlled encryption keys
Customer-controlled keys and staff-blind processing are design options, not current baseline features. They require separate technical validation, recovery planning, provider review, and pricing before they can be promised in an engagement.
For Regulated Industries
High-risk data requires a review before upload.
Do not submit protected health information, privileged legal material, payment-card data, government identifiers, or similarly high-risk content to the baseline portal. Those uses require a written security and compliance review before any data is uploaded.
Law firms & professional services
Law firms should exclude privileged or matter-sensitive material unless the firm approves the providers, access model, retention terms, and professional-responsibility requirements in writing.
Medical & healthcare
The current baseline service is not offered for Protected Health Information. A future healthcare engagement would require verified HIPAA-eligible configurations and signed Business Associate Agreements with every relevant party before processing PHI.
Enterprise & family offices
Dedicated tenancy, customer-controlled keys, data residency, and formal third-party assessment are not included in the baseline portal. They may be evaluated for a separately scoped deployment.
What We Don't Do
The promises that matter most are the ones written in the negative.
- We don't sell your data. Captured knowledge is not a product line. It is not packaged, anonymized, sold, or licensed to anyone.
- We don't train AI models on your data. We configure commercial AI services so customer material is not used for general model training, and we document the applicable provider terms in the engagement agreement.
- We don't share captured knowledge outside the engagement. Material is limited to authorized customer users, necessary service providers, and authorized KeyPersonAI administrators supporting the engagement.
- We don't claim certifications we haven't earned. Where the security model relies on a vendor's certification, we say so. Where formal attestation is on the roadmap rather than completed, we say that too.
Have a specific security question for your situation?
Most engagements have a security question or two that's worth a direct conversation. We'd rather answer in plain English than send a generic SOC 2 link.