Security

Connect without opening your estate
to us.

Integration is a protocol, not a catalogue. Start with no external connection, let your systems call Kumo, or run the outbound Kumo Connector beside the tools you choose to publish. The safety model stays the same: named users, scopes that only narrow, human confirmation, co-signature, and a complete audit trace.

GDPR alignment
UK ICO registered

We follow GDPR by design. DPA available on request.

SOC 2 Type I
In progress · target Q4 2026

Currently in observation window with our auditor.

SOC 2 Type II
Planned · post Type I

Will follow Type I; 12-month observation thereafter.

Independent pen-tests
Annual · most recent Mar 2026

Summary report available under NDA on request.

Integration security

Three levels. No forced connection.

Kumo is useful before it touches another system. When you connect one, the direction, credentials, published operations, and exit remain explicit.

Level 1 · Standalone

No external integration

Kumo web and mobile run on their own. No inbound port, no credentials to an external system, and no copy of an external database.

Level 2 · Inbound

Your systems call Kumo

They use a scoped Kumo credential. Their own system credentials remain where they already live; every request is role-bound and audited.

Level 3 · Outbound

Kumo calls named tools

A published MCP endpoint may use an encrypted scoped token. With the outbound Connector, the adapter and credentials stay inside your network and only TLS egress is required.

With the Kumo Connector

What never crosses the boundary.

The connector dials out. The local adapter is the contract: Kumo can call only the explicit, named tools you publish.

  • Your database, whole or partial
  • An inbound route, VPN, or firewall exception
  • Administrative credentials to the core system
  • Operational technology or physical-site networks
  • Anything not expressed as a named tool
  • A background sync or shadow source of truth
The technology surface

Four products. One governed platform.

The runtime, APIs, protocol layer, and embedding kit inherit the same identity, approval, encryption, and audit controls.

01Agent runtime

Kumo AI Platform

Kumo’s model, planner, durable run loop, approvals, co-signature, artifacts, memory, credits, and tamper-evident audit in one governed platform.

  • Named user on every request
  • Human gates on commitment
  • Complete correlated trace
Technical reference
02Application surface

Kumo API

Embed the complete Kumo Agent or call individual HR operations through a versioned REST and Agent API with delegated identity.

  • Agent API + REST
  • Resumable SSE + signed webhooks
  • Generated OpenAPI contract
Technical reference
03Universal integration

Kumo MCP

A matched server, client, and outbound Connector. Your systems call Kumo; Kumo calls the named tools you choose to publish.

  • Protocol, not a catalogue
  • No inbound port with Connector
  • Receipts, attribution, idempotency
Technical reference
04Embedding toolkit

Kumo HR Agent Kit SDK

A typed TypeScript client, headless controller, and accessible React panel for putting Kumo inside a customer application.

  • Short-lived delegated credentials
  • Stream reconnect + decisions
  • Webhook verification
Technical reference
Controls in production today

What we already do, without asterisks.

Everything below is live for every customer on every plan. We'll happily walk through any of it on a call, share architecture diagrams under NDA, or take a security questionnaire.

Encryption

Data is encrypted at rest and in transit, end-to-end, across the platform.

  • AES-256 at rest (database, blobs, backups)
  • TLS 1.3 in transit, HSTS preloaded
  • Customer-managed keys planned for enterprise

Authentication

Named users, short-lived delegated credentials, and immediate revocation.

  • Google & Microsoft sign-in
  • Email verification and MFA controls
  • API credentials are scoped, expirable, and shown once

Access & permissions

Role-based access control down to the field, with sensitive-action approvals.

  • Standard & custom RBAC roles
  • Field-level permissions for sensitive data
  • Time-bound elevation for support access

Audit log

Every agent step is encrypted, correlated, and written to a tamper-evident ledger.

  • Hash-chained events with signed JSON export
  • Searchable by run, request, action, tool, and user
  • Covers model, approval, API, MCP, connector, artifact, and credit activity

Data residency

Kumo's managed platform data is hosted in London today.

  • Region confirmed during the technical review
  • Connector-side source-system data stays in that system
  • Dedicated deployment is a separate architecture decision

Tenant isolation

Customer data is isolated at the application and storage layer.

  • Row-level isolation enforced in code & database
  • Dedicated tenant IDs on every record
  • Server-only integration and audit tables force RLS

Backups & resilience

Managed backups, durable run checkpoints, and explicit recovery behavior.

  • Database and object-storage backups
  • Agent runs checkpoint and recover after interruption
  • Connector failure leaves the source system untouched

Vulnerability management

External pen-tests, internal scanning, and a dedicated security on-call.

  • Annual third-party pen-test (last: Mar 2026)
  • Daily dependency & container scans
  • Critical CVE remediation SLA: 7 days

Uptime & resilience

Public status page, real incident comms, sensible targets.

  • Target 99.9% across the platform today
  • Status page with sub-component health
  • Formal SLA on Global / enterprise contracts
AI & data use

Your data trains nothing but your own answers.

Kumo AI is the most-asked-about part of our security posture. The short version: your data stays yours, the model only sees what your asking user is allowed to see, and every AI action is logged and reversible.

Not used for training

Your prompts and your data are used to answer your queries, full stop. They are not used to train Kumo's models or any third-party model.

Permission-aware retrieval

The AI retrieves only records the asking user is allowed to see, evaluated against the same RBAC layer as the rest of the platform.

Cited & explainable

Every AI answer cites the records it pulled. Every AI action explains its reasoning in plain language and surfaces what it changed.

Reversible by default

Any AI action can be rolled back in one click. Critical actions (pay changes, terminations) always require explicit human approval.

Subprocessors

Who else touches your data.

A current, honest list of every vendor we use to deliver Kumo. We'll notify you in writing before adding any new subprocessor that processes customer data.

Provider
Purpose
Hosting region
Amazon Web Services
Primary cloud hosting & storage
EU · UK · US · APAC
Cloudflare
CDN, DDoS, edge WAF
Global
Stripe
Billing & subscription management
EU · US
Anthropic
LLM inference for Kumo AI (no training)
EU · US
Postmark
Transactional email delivery
US (EU residency available)
Linear
Internal issue tracking (metadata only)
EU
Datadog
Observability & logging
EU

Last updated 26 May 2026. Want the change-log? Ask security@kumohr.com to add you to the subprocessor notification list.

Responsible disclosure

Found something? Tell us, please.

We treat security researchers as collaborators. If you've found a vulnerability, please report it via the channels below. We respond within one business day and won't take legal action for good-faith research.

Report a vulnerability in writing.

We accept reports via PGP-encrypted email or our HackerOne program. We'll acknowledge receipt within one business day, triage within three, and tell you what we're doing about it within ten. Hall-of-fame credit for valid reports; bounties for impactful ones.

@
security@kumohr.com

PGP key: 0xA1F0 3E92 …

Email
HackerOne program

Private invite available on request

Request invite
Trust documentation

DPA · sub-processor list · pen-test summary

Request

Want to go deeper?

Pen-test summaries, architecture diagrams, security questionnaire responses, all available on request.