How we protect your data

Security & trust

You're trusting Kezo with your content and your customers' conversations. Here's how we look after them, stated plainly, without badges we haven't earned yet.

Our practices

Encryption

Encrypted in transit

Everything on kezo.si is served over HTTPS with HSTS. Customer data in the service is encrypted in transit and at rest.

Privacy

Your data stays yours

We don't sell data and don't use your content to train models for anyone else. Delete an agent or your account and its data is removed within 30 days.

Access

Least-privilege access

Only the people who need access to run the service have it, and your agent works only from the content and rules you give it.

Masking

Sensitive numbers masked

Card numbers, bank account numbers (IBAN) and ID numbers a customer types are masked before they're stored or read by the AI.

Identity

Customer identity

Account data and actions need the customer to confirm their email with a one-time code. If your customers are signed in to your app, your app can vouch for them with a signed (HMAC) token instead.

Control

Actions with limits

Every action is Automatic, Ask me or Off, with money limits, daily caps and per-customer caps. Customers with a history of repeated refunds or complaints go to you before money moves. Calls to your own API are read-only.

Audit

Verified and audited

Every action Kezo takes is logged, then checked in your store or billing system. If it didn't go through, you're told and the conversation comes back to your inbox.

Complaints

Complaint register

Complaints are logged with a response deadline (general, EU/UK payment services 15 business days, UK FCA 8 weeks, US Reg E 10 business days, India RBI 30 days) and you're alerted before it's due.

Report

Responsible disclosure

Found a vulnerability? Email hello@kezo.si with "Security" in the subject. We respond within 2 business days.

Compliance

Kezo is in early access and is not yet SOC 2 certified. It's on our roadmap, and we'll publish it here when it's done rather than before. Kezo doesn't hold ISO 27001, PCI DSS or HIPAA certification either. Masking card and bank numbers protects your customers, but it doesn't make Kezo a payment processor, and the complaint register tracks deadlines for you; meeting your own regulatory obligations stays with you. We support GDPR and CCPA data requests today; see our Privacy Policy. Need a security questionnaire or a DPA? Contact us.

Infrastructure

The kezo.si website and app are served from Cloudflare's global network. The service's database and processing run on Supabase in the United States (AWS us-east-1), with data encrypted at rest. Keys for tools you connect are additionally encrypted with AES-256-GCM, with the key held outside the database. Email is delivered by Resend; business email runs on Google Workspace.