Security & trust

Security at Keld.

Keld optimises what your AI costs without ever taking ownership of your proprietary intelligence. We secure the economics of every job — pricing, matching and settlement — while your prompts and completions pass through only to run, and are never stored.

How your data flows

Control plane and data plane, separated.

Keld cleanly separates the control plane (the financial settlement: pricing, matching, the auditable record) from the data plane (the live delivery of your job). The control plane is where Keld operates; your content lives only in the data plane, for as long as the job runs.

01 · SUBMIT

You send a job

A job with a deadline and a ceiling, naming a model or use case. Keld sees the metadata it needs to price and match — not a place to keep your content.

02 · MATCH & ROUTE

Keld routes it

The marketplace matches your job to the best-value provider within your bounds and routes it for execution. Matching and settlement run on the control plane.

03 · EXECUTE & SETTLE

It runs, then clears

The provider runs the job and returns the result. Keld records an auditable settlement; the prompt and completion are not retained afterward.

Zero Data Retention

Prompts and completions are never stored, never logged, and never used for training. Keld secures the economics of the job, not its contents.

Encryption everywhere

All traffic is encrypted in transit (TLS), and the control plane is encrypted at rest. Access is least-privilege and logged.

Data residency & self-hosting

Pin where jobs are processed, or run Atlas self-hosted or air-gapped inside your own perimeter with full ZDR.

Subprocessors

Who helps us run Keld.

Keld uses a small set of subprocessors to operate the platform. We keep the list deliberately short and review it regularly.

CategoryPurpose
Cloud infrastructureHosting and running the Keld control plane.
Inference providersThe AI model providers in the marketplace that execute matched jobs within your bounds.
Product analyticsAggregate, privacy-respecting usage analytics for the website and console.

The current, named list of subprocessors — with entity, location and function — is available to customers and prospects under NDA. We notify customers of material changes before they take effect.

Compliance

Certifications & controls.

SOC 2 (Type II) — in progress

We're pursuing SOC 2 Type II covering security, availability and confidentiality. The audit is underway; current status is available under NDA.

GDPR

Built to support GDPR obligations, including a Data Processing Agreement, data-subject requests and EU data residency options.

Access & audit

SSO/SAML and role-based access control, with a complete, exportable audit trail for every job, model choice and spend decision.

Reviewing Keld for security?

We're happy to walk your security and compliance teams through our architecture, share our subprocessor list and SOC 2 status under NDA, and answer your questionnaire.