Where your data lives, and what we do not claim
KairosAI runs on AWS Mumbai, so your records, recordings and transcripts are stored in India. WhatsApp and Instagram messages travel through Meta's own infrastructure before they reach us, which is how Meta's API works for every vendor. Our full sub-processor register comes with the DPA, and we are DPDPA-aligned rather than formally certified.
What we hold ourselves to
- Your records are stored in India
Compute, the database, object storage and outbound email all run in AWS Mumbai (ap-south-1). Recordings and transcripts never leave it.
- One tenant cannot read another
Every table carries the tenant it belongs to and PostgreSQL row-level security enforces it at the database on a least-privilege role, so a query without a tenant context reads nothing at all. It is not an application-layer filter that a missing WHERE clause can defeat.
- Money and irreversible actions never auto-run
No matter how permissively an operator sets their risk threshold, recording a payment or issuing an e-invoice waits for a human. That ceiling lives in the action policy, not in a prompt.
- Every agent action lands on a hash-chained audit log
Tamper-evident: each entry chains to the one before it, so a deleted or edited row breaks the chain and is detectable.
- Retention is configurable, with honest defaults
Recordings default to 90 days, messages and transcripts to 365. You can shorten either.
- You can erase a tenant
A deletion request marks the tenant erased, frees its identifiers and stops all processing, ahead of the physical purge.
What we do not claim
You would find all of this in week two anyway. Finding it here is a different conversation from finding it in a questionnaire we answered optimistically.
- We are DPDPA-aligned, not certified
We follow the DPDP Act's principles and can show you how. No regulator or auditor has assessed us, and we do not hold a certificate that says otherwise.
- No SOC 2, no ISO 27001
Neither is in progress today. If your procurement requires one, we are not a fit yet and would rather say so before you spend a cycle on us.
- Messaging channels are not in India
WhatsApp and Instagram messages pass through Meta's own infrastructure before they reach us. That is how Meta's API works for every vendor, ours included, and it is listed below rather than left out.
- There is no on-premise or private-cloud deployment
Every tenant runs on our AWS account, on shared services. We do not offer dedicated infrastructure and we do not publish an uptime SLA.
- Self-serve data export is not built yet
Ask us and we will produce your data. There is no button for it, and we would rather tell you that than imply one exists.
Sub-processors
We keep a written register of every third party that can receive customer data, what it is used for, where it processes, and what agreement covers it. It forms an annexure to our data processing agreement.
We share it under NDA, and with every customer who signs a DPA. We do not publish it, because the specific vendors behind a feature are commercially sensitive. If your security review needs it before you sign, ask us and you will have it.
- Where the platform runs
- AWS Mumbai (ap-south-1). Records, recordings and transcripts do not leave it.
- WhatsApp and Instagram messages
- Traverse Meta's own infrastructure before they reach us, as they do for every vendor on Meta's API.
- Everyone else on the register
- Receives nothing unless the integration that needs it is switched on for your tenant.
Questions a page cannot answer: talk to us. The full terms are in the data processing agreement.