Trust & security

Your data stays in your cloud account.

When we build an AI system for you, it runs inside your own cloud account, on servers you control. Your documents are read and processed there. They are not copied to Kelsus, and they are not sent to any outside service. This page explains how that works, which security standards we meet today, and how we handle your information while a project is underway.

How it works

Where your data runs.

Four things are true on every project, whichever AI model we use and wherever your company operates.

Security standards

Where we stand on certifications.

Some security standards come with an outside audit, where an independent auditor checks how a company works and writes a report. Others are sets of controls a company follows on its own, with no outside report yet. For each standard below, we say which kind it is, so you can see what someone other than Kelsus has checked.

During a project

How we handle your information.

These are our standard practices. We write them into the contract for every project.

Sub-processors

Which outside companies handle your data.

A sub-processor is an outside company that handles data for us. Because your system runs in your own account, no sub-processor touches your data. The AI model, the search index, and the software that connects them all run inside your account, under your control.

To run our own business, meaning this website and our email newsletter, we use Amazon Web Services for hosting and email. That is separate from any customer project and never touches your data. If you would like the current list of outside companies we use, ask us and we will send it.

For your security team

Common questions.

Will you fill out our security questionnaire?
Yes. Send us your form and we will complete it. If you use a standard format such as SIG or CAIQ (two common security questionnaire formats), we can work from that as well.
Can we speak with a customer you have worked with?
Yes, when that customer agrees and signs off. We will introduce you to one whose situation looks like yours.
How do we report a security problem?
Email security@kelsus.com. That address reaches several people on our team, so a report does not wait on one person being available. We will reply within one business day and work through it with you. You can also use our contact form if you prefer.
Where does the system run?
In your own cloud account, on a private network. It uses standard cloud parts: servers with GPUs that run the AI model, a database that handles search, and a small service that connects them. Our reference architecture page walks through the whole setup if you want the detail.

Have a security question we did not cover?

Send it to us and we will answer it. We can also set up a call to go through the details with your team.