kimo
Trust centerUpdated 1 Oct 2026

Your data stays yours. Provably.

Kimo connects to your most sensitive systems: revenue, customers, and for some teams, mission data. Here is exactly how we protect it, from the first sync to the last dashboard.

See the architecture
Security posture
Continuously monitored controls
All systems normal
142 / 142
automated controls passing
Last external pentest: Sep 2026
  • Encryption at rest & in transitPass
  • SSO enforced for staffPass
  • Tenant isolationPass
  • Open critical findingsPass
  • Uptime, last 90 daysPass
Compliance

Where we stand, and what is next

Independent auditors check our controls every year. Reports are available under NDA from the document request form.

SOC 2

SOC 2 Type II

Security, Availability, Confidentiality

In progress

Type II audit in progress · readiness report under NDA

ISO

ISO/IEC 27001:2022

ISMS for the Kimo platform

In progress

Controls aligned with ISO/IEC 27001:2022 · certification planned

GDPR

GDPR

Processor & controller obligations

Ready

DPA with SCCs · EU data residency

HDS

HDS

French health data hosting

In progress

Certification audit scheduled Q1 2027

SNC

SecNumCloud-ready

Sovereign deployments

Ready

Runs on qualified providers · on-prem & air-gapped

Demo site: certifications and audit dates shown here are illustrative.

Architecture

Follow your data, end to end

Same product, four ways to run it. Pick a tenancy mode to see where the trust boundary moves.

Managed by Kimo
Kimo control planeLicensing, updates
  1. Your sources
    Databases, SaaS, files
  2. Encrypted sync
    TLS 1.3 · CDC · checksums
  3. Isolated workspace
    Per-tenant schema & KMS key
  4. Models
    Semantic layer · row policies
  5. Dashboards
    Charts · Ask Kimo · alerts
  6. Inside: Kimo Cloud · EU or US region
Data lives in
Kimo-managed region (EU or US)
Isolation
Logical: schema + key per workspace
Updates
Continuous, zero downtime
Best for
Most teams. Live in minutes, EU or US hosting.
Data handling

Encrypted by default, located by choice, deleted on schedule

At rest

Every workspace, backup and cache is encrypted with a dedicated data key, wrapped by a per-tenant master key.

AES-256-GCM · envelope encryption

In transit

TLS 1.3 everywhere, HSTS preloaded, and mutual TLS between internal services. Connectors support SSH tunnels and PrivateLink.

TLS 1.3 · mTLS · HSTS

Bring your own key

Enterprise workspaces can hold the master key in their own KMS or HSM. Revoke it, and Kimo can no longer read a byte.

AWS KMS · GCP KMS · HSM (PKCS#11)

Secrets & credentials

Source credentials live in a dedicated vault, are never logged, and are only decrypted inside the sync worker that needs them.

Vault · short-lived tokens

Data residency

Pinned per workspace at creation.

Primary
Gravelines, FR
Failover
Strasbourg, FR
Backups
Paris, FR (separate provider)
Support access
EU-based engineers only
Ask Kimo (AI)
EU-hosted model, zero retention
Framework
GDPR · no transfers outside the EU

Retention

Defaults, and what happens when you leave.

DataDefaultConfigurablePurged after offboarding
Synced source dataWhile connectedYes30 days
Query result cache24 hoursYesImmediate
Audit log13 monthsYesExported, then 30 days
Encrypted backups35 days, rollingFixed35 days
Ask Kimo questions90 daysYesImmediate
Application logs (scrubbed)30 daysFixed30 days
Access control

The right people, the right rows, a full paper trail

Identity comes from your IdP. Permissions are enforced in the query engine, not the UI, so an API call sees exactly what a dashboard sees.

SSO & SAML 2.0

Okta, Entra ID, Google Workspace or any SAML/OIDC provider. Enforce SSO and disable passwords per workspace.

SAMLOIDCMFA

SCIM provisioning

Users and groups sync from your IdP. Offboard someone there and their Kimo access is gone within a minute.

SCIM 2.0JIT

RBAC + ABAC

Roles for what people can do, attributes for what they can see: region = "EMEA", clearance ≥ "restricted".

RolesRow policiesColumn masks

Audit everything

Every login, query, export and permission change is logged, immutable, and streamable to your SIEM.

SplunkElasticWebhook
audit.log · workspace acme-demo
STREAMING
  • 09:41:00ZINFOsync.complete[email protected] → postgres-prod · 18,204 rows
  • 09:40:56ZWARNrole.grant[email protected] → analyst → editor
  • 09:40:52ZDENYpolicy.row.denysvc-sync-17 → region != EMEA
  • 09:40:48ZDENYpolicy.row.denyapi-key:ci-exports → region != EMEA
  • 09:40:44ZINFOexport.csvscim-okta → pipeline_q3 · masked: email
  • 09:40:40ZWARNscim.user.deprovision[email protected] → j.ortega
  • 09:40:36ZWARNscim.user.deprovision[email protected] → j.ortega
  • 09:40:32ZINFOdashboard.share[email protected] → board-pack → finance-leads
Simulated events · fictional workspace→ Splunk HEC · Elastic · S3 (WORM)
Status

Boringly reliable

Multi-zone, with automatic failover and a 99.9% SLA on Business plans (99.95% on Enterprise). Every incident gets a public post-mortem.

  • Web app & dashboardsOperational99.98%
  • REST APIOperational99.99%
  • Sync engineOperational99.95%
  • Ask KimoOperational99.97%
Kimo Cloud · all regions
Daily uptime, last 90 days (simulated)
99.98%
90-day uptime
90 days agoToday
OperationalDegraded performancePartial outage3 incidents · all with post-mortems
Subprocessors

Who else touches your data (short list)

We keep this list small and tell you 30 days before it changes.

SubprocessorPurposeDataLocationRegion
OVHcloudPrimary hosting (EU region)Customer dataGravelines & Strasbourg, FREU
ScalewayBackups & disaster recoveryEncrypted backupsParis, FREU
Google CloudHosting (US region only)Customer data (US tenants)Iowa, USUS
CloudflareCDN, WAF and DDoS protectionRequest metadataGlobal edge, EU logsEU + US
Mistral AILLM inference for Ask Kimo (opt-in)Questions + schema, no rowsParis, FREU
StripeBilling and paymentsBilling contactsDublin, IEEU + US
SentryError monitoring (scrubbed)Stack traces, no customer rowsFrankfurt, DEEU
IntercomIn-app support chatSupport conversationsDublin, IEEU
Get notified about subprocessor changes
Vulnerability disclosure

Found something? We want to hear it

Good-faith research is welcome and protected by our safe-harbor policy. Please do not access other customers’ data or degrade the service.

/.well-known/security.txtReport
Contact: mailto:[email protected]
Expires: 2027-10-01T00:00:00Z
Encryption: https://getkimo.example/pgp.asc
Preferred-Languages: en, fr
Policy: https://getkimo.example/security#disclosure
Acknowledgments: https://getkimo.example/security#hall-of-fame
PGP fingerprint4F2A 9C1D 7B3E 08A6 5D91 E2C4 3B7F 6A10 9E58 D3C2

Our response commitments

Acknowledge
< 24 h
Triage & severity
< 3 days
Fix critical
< 7 days
Fix high
< 30 days

Private bug bounty

Scope: *.getkimo.example, desktop agent
Critical
€3,000 – €10,000
High
€1,000 – €3,000
Medium
€250 – €1,000
Low
Swag + hall of fame

Hall of fame 2026

  • @nullbyte_nina
  • @k4tana
  • @fuzzyowl
  • @r0ot_cause
  • @ssrfox

Fictional researchers, real gratitude.

FAQ

What security teams ask us

Need a filled-in questionnaire? Request the CAIQ from the documents form.

Synced data is stored in your isolated workspace so dashboards are fast. You choose which tables sync and can switch any source to live query mode, where only aggregated results are cached.

Sovereign deployments

On-prem, air-gapped, accredited.

Kimo Defense Intelligence runs fully inside your enclave, with signed offline updates and zero phone-home.

Explore Kimo Defense
Security review

Everything your security team needs, in one request.

SOC 2 readiness summary, ISO 27001 SoA, pentest summary, DPA and a pre-filled questionnaire.

Talk to our security team