Data sovereignty
Kendraa is deployed as a dedicated, isolated environment for each organisation — hosted by us on your behalf, or inside your own AWS account. Either way, the evidence, documents, and investigative work product (“Customer Data”) live in your tenancy. Data is not copied into a shared multi-tenant store, not mirrored to other regions without your instruction, and not pooled across customers.
AI safety & isolation
The Copilot and other AI features run on a model hosted inside the workspace, air-gapped from the public internet for inference.
- Zero prompt egress. Prompts and document content are not sent to external LLM APIs.
- No training on your data. Your data is never used to train, fine-tune, or evaluate models outside your engagement.
- Assistive by design. AI output (search terms, summaries, suggested batches) is presented for human review — it informs the investigator’s judgement rather than replacing it.
Access control & accountability
- Role-based access control (RBAC). Users are granted least-privilege roles scoped to the matters they work on.
- Two-factor authentication. Email-based 2FA with trusted-device support can be enforced at the organisation level.
- Audit trail. Security-relevant actions are recorded to a defensible, per-matter audit trail so review decisions stay accountable.
- Tenant isolation. Each investigation’s case data is segregated, with access checks on every request.
Data protection
We use industry-standard encryption in transit and at rest for data held in the platform, and apply technical and organisational measures appropriate to the sensitivity of legal evidence. Our handling of personal data is described in the Privacy Policy.
Infrastructure
The platform runs on Amazon Web Services. Deployments are isolated per customer, and the architecture is designed so that case data and AI inference stay within the customer’s environment.
Compliance & due diligence
We’re happy to support your security and procurement due diligence. For security questionnaires, a current sub-processor list, architecture detail, or a data-processing agreement, contact us and we’ll work through your requirements.
Responsible disclosure
If you believe you’ve found a security vulnerability, please report it to hello@kendraa.co.in. We ask that you give us a reasonable opportunity to investigate and remediate before any public disclosure. We will not pursue good-faith researchers who act responsibly.
Contact
Security questions or a due-diligence request? Write to hello@kendraa.co.in.