Trust Centre · Last reviewed April 2026
Your data, in safe hands.
Kaizan listens to client conversations. That is a serious responsibility. Below: how we secure
your data, how we handle privacy, and how we govern the AI behind the product.
Security
ENCRYPTION · IN TRANSIT & AT REST
TLS 1.2+
Every request, every region
AES-256
Per-tenant keys in AWS KMS
BYOK
Customer-managed keys on Enterprise
Pen test
Quarterly third-party
AUDIT LOG · LAST 60 SECONDS
12:04:18 admin@northwind.com role.update kz-care-001 → manager
12:04:09 jdoe@hooli.io session.start sso · okta
12:03:55 sec-bot access.review weekly · ok
12:03:41 priya@pied-piper.com export.audit 180 events · csv
12:03:22 ops@kaizan.ai access.granted ttl 30m · ticket #4218
🏅
Accreditations
Your trust is imperative to us. Kaizan is SOC 2 certified and an approved integration
partner with Microsoft & Google workspaces so you can be sure your company’s data is in good hands.
Our Trust Centre provides up to date info on the status of our accreditations.
🛡
Protection
AES-256 at rest, TLS 1.2+ in transit, per-tenant encryption keys in AWS KMS. Optional
customer-managed keys (BYOK) on Enterprise. Quarterly third-party penetration tests with summaries
available under NDA.
🔑
Access
Engineers do not have routine access to client data. Production access is explicit,
time-bounded, logged in an immutable audit trail, and reviewed weekly. SSO + SCIM enforced on Growth and
Enterprise plans, with role-based permissions and customer-configurable retention.
Privacy
KAIZAN · TRUST CENTER SHARE · SUBSCRIBE
Risk Profile
Data access Restricted
Impact Moderate
RTO 8 hours
Product Security
Audit logging ✓
Data Privacy ✓
Integrations ✓
Reports
SOC 2 Type II PDF
Pen test PDF
Questionnaire PDF
Self-Assessments
SIG Lite ✓
CAIQ ✓
VSA ✓
Data Security
Access mon. ✓
Backups ✓
Erasure ✓
App Security
Bot Detection ✓
Vuln Mgmt ✓
WAF ✓
POLICY · v4.2 · APR 2026
Data Processing Agreement Standard DPA · MNDA in
<24h
Privacy Policy Plain English · reviewed
quarterly
Sub-processor list 8 vendors · 30-day notice on
change
Retention 30 days → 7 years · configurable
Right to erasure Self-serve in product · within
30 days
CONSENT · ANYTHING IS POSSIBLE LTD
What Kaizan holds for this client
Meeting transcripts
142 calls · last 12 months
Email threads
218 threads · last 90 days
CRM signals
HubSpot · open + closed deals
Slack channels
Excluded by allow-list
⚖
Compliance
Kaizan complies with leading industry standards and regulations, including SOC 2, GDPR,
and the EU-U.S. Data Privacy Framework. Regular audits and third-party assessments help us maintain and
improve our security posture.
📄
Policy
Plain-English Data Processing Agreement and privacy policy, reviewed quarterly. Material
changes are notified to enterprise customers 30 days in advance with the right to object. Standard MNDA
turnaround typically under 24 hours.
👍
Consent
Granular consent surfaces inside the product. Account managers and clients can review what
data Kaizan holds about a relationship and request deletion at any time. Per-meeting opt-outs supported
via calendar invite tags.
AI
CUSTOMER DATA · ISOLATED PER TENANT
Tenant A
Tenant B
Tenant C
Tenant D
Tenant E
MODELS IN PRODUCTION · RISK-RATED
kz-care-summary GPT-4o · zero
retention LOW 99.4%
kz-risk-classifier Claude 3.7 · zero
retention LOW 97.8%
kz-expansion-rank Claude 3.7 · zero
retention MEDIUM 94.1%
kz-draft-followup GPT-4o · zero
retention MEDIUM 92.6%
YOUR DATA
Per-tenant · isolated
Encrypted · BYOK optional
×
NEVER USED FOR TRAINING
FOUNDATION MODELS
OpenAI · Anthropic
Zero-retention API
🗄
Data Isolation
Your data is not used for training AI models. We ensure complete isolation of customer
data from the data sets used to develop, enhance and deliver our AI capabilities.
🧭
Model Governance
Every model in production is risk-rated, version-controlled and monitored. New models go
through pre-launch evaluations covering accuracy, bias, refusal behaviour and prompt-injection
resistance. Audit logs of model decisions are retained per your retention policy.
🔑
Model Training
Kaizan does not aggregate client data to train shared or foundation models. Per-tenant
fine-tuning, when explicitly enabled, stays scoped to that tenant and is deleted on contract end.
Zero-retention API contracts with OpenAI and Anthropic.