Security, residency, and ownership.

How kis.ai keeps enterprise AI inside your infrastructure — our certifications, where your data lives, the deployment models you can choose, and what it means to own your intelligence layer.

Security & certifications

Independently audited and attested — with the platform designed so we never touch your data.

SOC 2 Type II
Certified & attested
ISO 27001
Certified & attested
ISO 22301
Certified & attested
Aligned to
HIPAAFedRAMPGDPRNIST 800-53PCI DSSEU AI ActDORAISO 42001
Certifications
ISO 27001, ISO 22301, SOC 2 Type II
Independently audited and attested
Data-plane access
kis.ai never accesses your data plane
By deployment design, across every model
Audit logging
Every control- and observability-plane action is recorded
Signed, append-only audit trail
Security measures
Technical, organizational and administrative controls
Continually improved in line with technological developments
Read the full Privacy Statement

Data residency

Your data stays where you put it — inside your own infrastructure, with zero egress by default.

Where your data lives
Inside your own infrastructure
On-prem, air-gapped, or your cloud VPC — your choice
Data egress
Zero by default
Nothing leaves your environment unless you call a frontier API you choose
Cross-border transfers
Governed by Standard Contractual Clauses
Only where lawful, with adequate safeguards
GDPR
Full data-subject rights supported
Access, rectification, erasure and portability

Deployment options

Choose the deployment model that fits your security and operational requirements. In every model, kis.ai has no access to your data plane and every privileged action is recorded for audit.

Kisai Cloud

Managed Cloud

Isolated, single-tenant instances hosted and operated by kis.ai.

  • Complete tenant isolation with dedicated instances
  • kis.ai has no access to your data plane
  • kis.ai operates the control and observability plane
  • Every control- and observability-plane action recorded for audit
Private Virtual Cloud

Private VPC / BYOC

Runs in your own cloud VPC on AWS, Azure, or GCP.

  • Hosted in your AWS, Azure or GCP VPC
  • kis.ai has no access to your data plane
  • You grant control- and observability-plane access, revocable anytime
  • Every control- and observability-plane action recorded for audit
Customer Data Center

On-Premise

Deployed within your own data center, air-gap capable.

  • Hosted in your own data center
  • kis.ai has no access to your data plane
  • You grant control- and observability-plane access, revocable anytime
  • Every control- and observability-plane action recorded for audit

Own the intelligence too, not just the apps.

Your knowledge, your models, and the extracted intelligence belong to you — exportable and yours to keep.

Model weights
You own your fine-tuned weights
Retrain or upgrade the base model on your schedule
Your data
Never trains anyone else's model
Fine-tuning runs inside your environment, on your data
Where it runs
On your infrastructure, never taken away
No provider can deprecate a model out from under you
Portability
Swap any model without rebuilding your apps
Weights, data, prompts and logs stay on your hardware

Data handling

What we do, and what we don’t do, with your data.

We do
  • Keep your data and models inside your environment
  • Apply technical, organizational and administrative security controls
  • Support access, rectification, erasure and portability requests
  • Delete your personal data within one month of a request
  • Record every control- and observability-plane action for audit
We don’t
  • Access your data plane
  • Use your data to train anyone else's model
  • Disclose your information to third parties for their promotional purposes
  • Meter or monetize your usage
  • Deprecate or take your models away
“Trust isn’t a promise. It’s your infrastructure, your models, and an audit trail you can verify.”