Trust

Security at Kenda

Last updated 2026-07-27

Key access

Kenda connects to your AI providers with read-only scopes only. We never request write access, and a connected key can be revoked from your provider at any time. We recommend a dedicated key per integration so access stays least-privilege and auditable.

What we store

We ingest token-usage metadata: counts, model, timestamp, and the identity dimensions you attribute by (agent, team, workflow, key). We do not store the raw prompts or completions that pass through your agents. Spend is computed against an effective-dated price book and reconciled to your provider invoice. We also keep service metadata for the credentials you create in Kenda: the name you give one, a masked suffix, and when it was created and last used.

Encryption

Data is encrypted in transit (TLS 1.2+) and at rest. Access to production data is scoped to the minimum set of operators needed to run the service and is logged.

Compliance

SOC 2 is planned for general availability. We will publish the report here when it completes; until then we will not claim a certification we do not hold. For a security review, data-processing agreement, or questionnaire, email lara@kenda.app or sebastian@kenda.app.