Security Overview
Kimpton AI's security architecture, AES-256 encryption standards, data isolation controls, and compliance posture for institutional buy-side investors.
Kimpton AI is built for buy-side portfolio managers who work with some of the most sensitive data in financial services: portfolio holdings, private research, mandate files, and proprietary investment theses. Every layer of the platform is designed with that responsibility in mind: your data is encrypted, isolated to your workspace, and never used to train AI models. You stay in control of what context the AI sees and when.
Core security principles
AES-256 Encryption
All data stored on Kimpton's infrastructure is encrypted at rest using AES-256. Data in transit is encrypted using the same standard, protecting your information end-to-end.
Data Isolation
Every resource in Kimpton, from portfolio snapshots to Vault documents and research sessions, is scoped to your user account or team workspace. No cross-workspace access is permitted.
No Model Training on Your Data
Kimpton's AI models are never trained on your documents, portfolio holdings, research outputs, or any other content you bring into the platform. Your firm's information remains yours.
Read-Only Brokerage Access
Kimpton connects to your brokerage via Plaid using a read-only OAuth flow. Kimpton cannot place trades, move funds, or take any action on your accounts. The platform is purely observational.
You control what the AI sees
Vault documents and portfolio data are only used as AI context when you explicitly enable them for a session. Kimpton does not silently inject your holdings or private research into every query. You decide what information is in scope at any given time.
When you want a specific document in scope, reference it directly: type @ in the composer and pick it. That pins exactly the file you meant rather than relying on search to surface it, and it never widens your access. If you couldn't open the document yourself, Kimpton won't read it for you.
Compliance posture
Kimpton maintains a dedicated compliance portal at trust.kimpton.ai where you can review the platform's current security documentation, controls, and status reports.
Kimpton has completed its SOC 2 Type II review. Visit trust.kimpton.ai for the current report and the underlying controls, or contact security@kimpton.ai if your diligence process needs something the portal doesn't cover.
Enterprise customers can request a Data Processing Agreement (DPA) to formalize data handling obligations under applicable privacy regulations. The standard DPA is available at kimpton.ai/dpa.
Legal documents
The following agreements govern how Kimpton collects, processes, and protects your data:
- Privacy Policy — kimpton.ai/privacy
- Terms of Service — kimpton.ai/terms
- Data Processing Agreement — kimpton.ai/dpa
- Fair Use Policy — kimpton.ai/fair-use
Reporting a security issue
If you believe you have discovered a security vulnerability or have a concern about how Kimpton handles your data, contact the team directly at security@kimpton.ai. For formal compliance documentation, security questionnaires, and audit reports, visit trust.kimpton.ai.
Explore security topics
Data Handling
Learn how Kimpton stores, processes, and protects your portfolio data, Vault documents, and research outputs.
Security FAQ
Answers to common questions from institutional investors about privacy, compliance, and data control.
Compliance Portal
Review Kimpton's security controls, certifications, and current compliance status.
Data Processing Agreement
Formalize data-handling obligations for your organization under applicable privacy regulations.
Introduction
Kimpton AI is an investment research platform for buy-side teams: AI-generated trade proposals, deep research, live dashboards, and investor-ready reports, grounded in your portfolio and mandate.
Data Handling
How Kimpton AI stores, processes, and protects your portfolio holdings, Vault documents, research sessions, and connections to third-party data providers.