Your data stays in your own cloud.
Kernyl is installed in your cloud, not ours. This page is written for your security review: the architecture, where data goes, and what we can and can't see.
Architecture
Where your data goes
People open Kernyl in a browser or the Mac app and connect to your installation over HTTPS. They sign in through your identity provider, and sessions expire after inactivity or a maximum age.
Messages, issues, pages and settings are stored in a database in your account, and uploaded files in your account's file storage. Both are encrypted at rest by your cloud, with keys you control.
Kernyl checks its license with us on a regular schedule. That check-in carries the version, a health flag and the number of active and named users. It never includes messages, issues, documents, files or names.
What happens when someone asks Kernyl
- A person asks a question, or asks for a summary.
- Kernyl checks, at that moment, which channels, issues and pages that person can open.
- It retrieves relevant passages from those sources only.
- It sends the question and those passages to an AI model in your own cloud.
- The answer comes back with numbered sources that link to the originals.
@Kernyl in a channel goes one step further: it only uses content every member of that channel can see. More on how Kernyl AI works.
For your security questionnaire
Short answers you can copy. We'll go deeper on a call.
- Deployment model
- Installed in your own cloud. We don't operate a hosted version.
- Components
- Kernyl, its database, file storage and AI models, all managed services in your own cloud.
- Data location
- Your cloud, in the region you choose.
- Data sent to the vendor
- License check-ins only: version, a health flag, and active and named user counts.
- Vendor access to production
- None. We hold no login to your installation; you decide what to share for support.
- Authentication
- Single sign-on with Google Workspace or OpenID Connect, restricted to your domains.
- SAML and SCIM
- Not available yet.
- Session management
- Idle and maximum session lifetimes, a device list for each person, and sign out everywhere for admins.
- Audit logging
- An audit log of administrative actions.
- Encryption in transit
- HTTPS between clients and your installation.
- Encryption at rest
- Your cloud's encryption for the database and file storage, with keys you control.
- AI processing
- AI models in your own cloud. Permissions checked at question time. Content is not sent to us.
- Third-party services
- Google, only if you connect Google Calendar or use Google sign-in.
- Clients
- Web browsers and a Mac desktop app. No mobile apps yet.
FAQ
Is our data used to train AI models?
Not by us: we never receive it. Kernyl calls AI models that run in your own cloud, under your own agreement with your cloud provider.
Who installs and updates Kernyl?
We set it up with your team during the install. Releases and model updates are included in your subscription.