Security & trust
You're trusting Kezo with your content and your customers' conversations. Here's how we look after them, stated plainly, without badges we haven't earned yet.
Our practices
EncryptionEncrypted in transit
Everything on kezo.si is served over HTTPS with HSTS. Customer data in the service is encrypted in transit and at rest.
PrivacyYour data stays yours
We don't sell data and don't use your content to train models for anyone else. Delete an agent or your account and its data is removed within 30 days.
AccessLeast-privilege access
Only the people who need access to run the service have it, and your agent works only from the content and rules you give it.
MaskingSensitive numbers masked
Card numbers, bank account numbers (IBAN) and ID numbers a customer types are masked before they're stored or read by the AI.
IdentityCustomer identity
Account data and actions need the customer to confirm their email with a one-time code. If your customers are signed in to your app, your app can vouch for them with a signed (HMAC) token instead.
ControlActions with limits
Every action is Automatic, Ask me or Off, with money limits, daily caps and per-customer caps. Customers with a history of repeated refunds or complaints go to you before money moves. Calls to your own API are read-only.
AuditVerified and audited
Every action Kezo takes is logged, then checked in your store or billing system. If it didn't go through, you're told and the conversation comes back to your inbox.
ComplaintsComplaint register
Complaints are logged with a response deadline (general, EU/UK payment services 15 business days, UK FCA 8 weeks, US Reg E 10 business days, India RBI 30 days) and you're alerted before it's due.
ReportResponsible disclosure
Found a vulnerability? Email hello@kezo.si with "Security" in the subject. We respond within 2 business days.
Compliance
Kezo is in early access and is not yet SOC 2 certified. It's on our roadmap, and we'll publish it here when it's done rather than before. Kezo doesn't hold ISO 27001, PCI DSS or HIPAA certification either. Masking card and bank numbers protects your customers, but it doesn't make Kezo a payment processor, and the complaint register tracks deadlines for you; meeting your own regulatory obligations stays with you. We support GDPR and CCPA data requests today; see our Privacy Policy. Need a security questionnaire or a DPA? Contact us.
Infrastructure
The kezo.si website and app are served from Cloudflare's global network. The service's database and processing run on Supabase in the United States (AWS us-east-1), with data encrypted at rest. Keys for tools you connect are additionally encrypted with AES-256-GCM, with the key held outside the database. Email is delivered by Resend; business email runs on Google Workspace.