Security

How we handle data today, and what's planned as Kuki Core moves toward general availability.

Data storage

Kuki OSS runs entirely on infrastructure you control, we never receive or store your data. For Kuki Core (in development), data is stored in isolated, per-tenant storage with encryption at rest.

Encryption

All traffic to and from Kuki is encrypted in transit via TLS. Encryption-at-rest for Core and Kuki's Clouds is planned ahead of general availability.

Access controls

Kuki OSS access is governed entirely by however you deploy it. Core will support role-based access controls and audit trails at launch.

Compliance

Kuki is early-stage and does not yet hold formal compliance certifications (e.g. SOC 2, ISO/IEC 27001, ODPC Registration, etc.). This is on the roadmap ahead of Core's general availability, reach out if you need specifics for your own review.

Found a vulnerability? Report it to security@kuki.co.ke.