Keld optimizes what your AI costs without ever taking ownership of your proprietary intelligence. We secure the economics of every activity (pricing, matching and settlement) while your prompts and completions pass through only to run, and are never stored. This is the hub for how we handle security, data and compliance.
Keld cleanly separates the control plane (the financial settlement: pricing, matching, the auditable record) from the data plane (the live delivery of the work). The control plane is where Keld operates; your content lives only in the data plane, for as long as execution runs.
Keld Signal detects the activities behind each prompt on your own machines and sends labels only — activity type, workstream, model, tokens. Prompt content never leaves your environment.
The marketplace matches each activity to the best-value provider within your bounds, using the labels it needs to price and match. Matching and settlement run on the control plane.
The provider runs the work and returns the result. Keld records an auditable settlement; the prompt and completion are not retained afterward.
Prompts and completions are never stored, never logged, and never used for training. Keld secures the economics of the work, not its contents.
All traffic is encrypted in transit (TLS), and the control plane is encrypted at rest. Access is least-privilege and logged.
Pin where work is processed, or run Atlas self-hosted or air-gapped inside your own perimeter with full ZDR.
Keld uses a small set of sub-processors to operate the platform: cloud infrastructure, the inference providers that execute jobs, and a few tools for analytics and communications. We keep the list deliberately short and review it regularly.
The named, current list (with sub-processor, purpose and location) is published at keld.co/subprocessors, where you can also subscribe to change notifications. We notify customers of material changes before they take effect.
We're pursuing SOC 2 Type II covering security, availability and confidentiality. The audit is underway; current status is available under NDA.
We're aligning our information-security management system to ISO/IEC 27001 with the goal of certification. Status is available under NDA.
Built to support GDPR and CCPA/CPRA obligations, including our Data Processing Agreement, data-subject requests and EU data residency options. See our Privacy Notice.
SSO/SAML and role-based access control, with a complete, exportable audit trail for every activity, model choice and spend decision.
Optimization is only useful if quality holds. Keld continuously evaluates the responses your optimized models produce against your own quality bar, so routing an activity to a cheaper provider or model never means a worse answer than your premium model would have given. You keep the economics of the marketplace without trading away the result.
Inference payloads stream from the demand side directly to the matched provider on the supply side. Keld processes that payload only to route and run it, under Zero Data Retention: nothing is kept once execution completes. For data that must stay in a region, region-pinning controls let you constrain where work runs; broader residency options are expanding as more providers come online.
For the most sensitive environments, deploy Atlas inside your own perimeter, self-hosted or fully air-gapped. You control the infrastructure and the data residency, choosing exactly where every activity runs, with full Zero Data Retention support end to end. Security and finance keep a complete, exportable audit trail of every activity, model choice and spend decision, so you can always see exactly what ran, where it ran and why.
AI regulation is tightening: the EU AI Act's phased obligations, data-residency rules, and a growing patchwork of restrictions on where models run and where they originate. On Keld these aren't roadblocks; they're just more bounds on the work. Alongside price and quality, you can constrain routing by jurisdiction, data residency, and model or provider origin, so every activity clears only on models and providers that meet your obligations.
Pin work to approved regions and residency zones, so nothing clears outside the boundary you set.
Filter by model or provider origin. As jurisdictions restrict models by where they come from, you encode the rule once and every activity honours it.
Route only to models and providers that meet your compliance bar: an enrichment parameter Keld curates, not a policy you police by hand.
Your regulatory constraints become curation parameters in the marketplace: set them once and Keld keeps every activity inside them, adapting as the rules evolve.
| Resource | What it covers |
|---|---|
| Privacy Notice | How we handle personal data; your rights under GDPR and CCPA/CPRA. |
| Cookie Policy | Every cookie we use and how to control it. |
| Sub-processors | The vendors and providers that help us run Keld. |
| Data Processing Agreement | Customer-facing DPA template (Article 28, SCCs). Pending legal review. |
| Acceptable Use Policy | What's allowed on the marketplace, and who's responsible. |
| Terms of Service | The agreement governing use of Keld. |
| System status | Live availability and incident history. |
We're happy to walk your security and compliance teams through our architecture, share our subprocessor list and SOC 2 status under NDA, and answer your questionnaire.