No external integration
Kumo web and mobile run on their own. No inbound port, no credentials to an external system, and no copy of an external database.
Integration is a protocol, not a catalogue. Start with no external connection, let your systems call Kumo, or run the outbound Kumo Connector beside the tools you choose to publish. The safety model stays the same: named users, scopes that only narrow, human confirmation, co-signature, and a complete audit trace.
We follow GDPR by design. DPA available on request.
Currently in observation window with our auditor.
Will follow Type I; 12-month observation thereafter.
Summary report available under NDA on request.
Kumo is useful before it touches another system. When you connect one, the direction, credentials, published operations, and exit remain explicit.
Kumo web and mobile run on their own. No inbound port, no credentials to an external system, and no copy of an external database.
They use a scoped Kumo credential. Their own system credentials remain where they already live; every request is role-bound and audited.
A published MCP endpoint may use an encrypted scoped token. With the outbound Connector, the adapter and credentials stay inside your network and only TLS egress is required.
The connector dials out. The local adapter is the contract: Kumo can call only the explicit, named tools you publish.
The runtime, APIs, protocol layer, and embedding kit inherit the same identity, approval, encryption, and audit controls.
Kumo’s model, planner, durable run loop, approvals, co-signature, artifacts, memory, credits, and tamper-evident audit in one governed platform.
Embed the complete Kumo Agent or call individual HR operations through a versioned REST and Agent API with delegated identity.
A matched server, client, and outbound Connector. Your systems call Kumo; Kumo calls the named tools you choose to publish.
A typed TypeScript client, headless controller, and accessible React panel for putting Kumo inside a customer application.
Everything below is live for every customer on every plan. We'll happily walk through any of it on a call, share architecture diagrams under NDA, or take a security questionnaire.
Data is encrypted at rest and in transit, end-to-end, across the platform.
Named users, short-lived delegated credentials, and immediate revocation.
Role-based access control down to the field, with sensitive-action approvals.
Every agent step is encrypted, correlated, and written to a tamper-evident ledger.
Kumo's managed platform data is hosted in London today.
Customer data is isolated at the application and storage layer.
Managed backups, durable run checkpoints, and explicit recovery behavior.
External pen-tests, internal scanning, and a dedicated security on-call.
Public status page, real incident comms, sensible targets.
Kumo AI is the most-asked-about part of our security posture. The short version: your data stays yours, the model only sees what your asking user is allowed to see, and every AI action is logged and reversible.
Your prompts and your data are used to answer your queries, full stop. They are not used to train Kumo's models or any third-party model.
The AI retrieves only records the asking user is allowed to see, evaluated against the same RBAC layer as the rest of the platform.
Every AI answer cites the records it pulled. Every AI action explains its reasoning in plain language and surfaces what it changed.
Any AI action can be rolled back in one click. Critical actions (pay changes, terminations) always require explicit human approval.
A current, honest list of every vendor we use to deliver Kumo. We'll notify you in writing before adding any new subprocessor that processes customer data.
Last updated 26 May 2026. Want the change-log? Ask security@kumohr.com to add you to the subprocessor notification list.
We treat security researchers as collaborators. If you've found a vulnerability, please report it via the channels below. We respond within one business day and won't take legal action for good-faith research.
We accept reports via PGP-encrypted email or our HackerOne program. We'll acknowledge receipt within one business day, triage within three, and tell you what we're doing about it within ten. Hall-of-fame credit for valid reports; bounties for impactful ones.
Pen-test summaries, architecture diagrams, security questionnaire responses, all available on request.