SECURITY

Private by architecture,
not by promise.

Legal evidence carries every kind of risk — privilege, PII, financial. So with Kendraa, privacy isn’t a setting you trust us to honour. It’s how the platform is built: deployed in your own environment, air-gapped, with the AI running offline.

Your environment

A dedicated, isolated deployment — hosted by Kendraa or in your own AWS account. Your data is stored in your environment, never copied out or mirrored elsewhere.

Air-gapped AI

The AI model runs offline inside the workspace. Your prompts never leave — not for inference, not for telemetry. Zero prompt egress, no third-party API callbacks.

Never trained on your data

We don’t train models on your data, sample it, or share it. You remain its sole master, end to end.

Data sovereignty

Kendraa is deployed as a dedicated, isolated environment for each organisation — hosted by us on your behalf, or inside your own AWS account. Either way, the evidence, documents, and investigative work product (“Customer Data”) live in your tenancy. Data is not copied into a shared multi-tenant store, not mirrored to other regions without your instruction, and not pooled across customers.

AI safety & isolation

The Copilot and other AI features run on a model hosted inside the workspace, air-gapped from the public internet for inference.

Access control & accountability

Data protection

We use industry-standard encryption in transit and at rest for data held in the platform, and apply technical and organisational measures appropriate to the sensitivity of legal evidence. Our handling of personal data is described in the Privacy Policy.

Infrastructure

The platform runs on Amazon Web Services. Deployments are isolated per customer, and the architecture is designed so that case data and AI inference stay within the customer’s environment.

Compliance & due diligence

We’re happy to support your security and procurement due diligence. For security questionnaires, a current sub-processor list, architecture detail, or a data-processing agreement, contact us and we’ll work through your requirements.

Responsible disclosure

If you believe you’ve found a security vulnerability, please report it to hello@kendraa.co.in. We ask that you give us a reasonable opportunity to investigate and remediate before any public disclosure. We will not pursue good-faith researchers who act responsibly.

Contact

Security questions or a due-diligence request? Write to hello@kendraa.co.in.