Security & standards

Security posture and engineering standards.

KynticAI deploys inside your boundary, keeps operational data close to the systems that own it, and shares security evidence with your team during procurement. This page states the posture plainly — what we do, how we build, and how we work with your security team.

Boundary

Customer data stays in the customer estate

TLS

Traffic protected in transit

Vaults

Credentials held close to source systems

Audit

Source trails and decision paths recorded

Security posture

Designed to stay inside the boundary your security team approves.

These are the control points we build to in every deployment. The list is specific because your security team will hold us to it — that is the point.

Customer data boundary

The control plane handles accounts, licences, updates, support, and aggregate usage metadata. Connector credentials, source records, relationship facts, and private configuration stay close to the systems that own the work — not in a hosted service by default.

TLS in transit

Traffic is protected with TLS. Production deployments terminate TLS at the estate edge and encrypt transport between components to the estate standard.

Encryption at rest

Storage encryption follows the estate standard set during deployment. Where the customer estate sets the bar, we build to it — not around it.

Credential vaults

Connector credentials and service secrets sit in vaults close to the source systems, with role and purpose controls on who can use them.

Role-based access

Access is granted by role and purpose for each deployment. What a system can reach, and who can act on it, is defined up front and documented.

Audit trails

Source trails, decision paths, and audit exports travel with the work. A human can answer why a recommendation was produced and what it was based on.

Engineering & technical standards

The standards we actually build to.

These are the engineering practices behind the product. Each one is verifiable — your engineers can check them against the code and the evidence packs.

Schema-validated output

Packets are validated against a versioned JSON shape — for example kynticai.relationship-analysis.example.v1 — before they count as product evidence.

OpenAPI and GraphQL

Integration contracts are published as OpenAPI and GraphQL with typed clients in TypeScript and C#. Developers see the exact shape before they build.

Reproducible runs

Evidence runs are repeatable: the same inputs produce the same packet shapes and confidence bands. A failed validation is a failed run, not a story.

Semantic versioning

Schemas and evidence packs are versioned so the shape a buyer reviewed is the exact shape they can reproduce.

Provenance levels

Outputs carry provenance levels (L0–L3) so the closeness of a claim to source-backed evidence is visible, not assumed.

Documentation as standard

Run logs, deployment topology, and access-controlled documentation accompany every go-live — the same bar we hold in regulated environments.

Governance & data handling

How data is handled, and who is accountable.

Commitments that go into the written agreement — not slogans on a page.

  1. 01

    Written scope

    You get a written scope with a fixed price before build. Nothing changes without your sign-off.

  2. 02

    DPA and security review

    A data processing agreement, security review, and acceptance checks are agreed in writing before a pilot or deployment.

  3. 03

    Retention and deletion

    Retention windows and deletion on termination are agreed in writing and honoured when the work ends.

  4. 04

    Incident response

    Security incidents are reported to the affected customer promptly, with investigation and remediation handled under the agreement.

Report a security issue

If you find a vulnerability in KynticAI software, report it to paul@kynticai.com. Reports are acknowledged and reviewed directly. Public disclosure is coordinated so customers have time to update before details are shared.

For your security team

Evidence on request, grounded in documents.

Procurement is where trust is tested. We publish no certification badge we do not hold, and we share current status and evidence with your security team under NDA — so the conversation is grounded in documents, not marketing.

  1. 01

    Public posture

    This page states what we do and how we build. Standards and boundaries are named, not implied.

  2. 02

    Security questionnaire

    Current certification status and security questionnaire responses are prepared for your team and shared under NDA during procurement.

  3. 03

    Technical walkthrough

    Run logs, deployment topology, and connector-specific evidence under NDA or scoped access.

  4. 04

    Customer pilot

    Authorised sources, written success measures, and outcomes measured in the estate.

The entity behind the work

KynticAI Limited

Registered in England and Wales, company number 17239903. Registered office: Flat 4, 19 Ranelagh Street, Liverpool, L1 1JW.

Security contact: paul@kynticai.com

Next step

Talk the posture through with the team.

The fastest route is a 20-minute technical discussion: bring your security team’s questions and we will answer them with evidence, not reassurance.

Proof and boundaries: Proof & validation · Architecture: Platform architecture