Security
Your data is yours. Read-only access, no model training, revocable connections, encryption at rest and in transit. SOC 2 Type II complete.
The controls
Read-only access
No model training
Revocable connections
SOC 2 Type II
End-to-end encryption
Tenant isolation
Data encrypted at rest with AES-256 and in transit with TLS 1.2+. SOC 2 Type II complete.
Four commitments that govern every design decision we make about your data.
How we think about your data
Kimpton can only view your holdings and historical transactions. No trading, no transfers, no changes. Portfolio connections use read-only integrations so there is complete separation from your assets.
Your portfolio data, research queries, and analysis results are never used to train AI models. We use commercial AI models with strict data processing agreements that prohibit training on customer data.
Your data is walled off from every other customer. Analysis runs in a private sandbox, and Kimpton employees do not have default access to customer portfolios. Any access requires specific, individual authorization.
Disconnect a portfolio connection at any time and the associated holdings and transactions are immediately deleted. Need a full account deletion? Email security@kimpton.ai.
Infrastructure & compliance
Single sign-on via Auth0. Multi-factor authentication. Session management with automatic expiration.
AES-256 encryption at rest, managed by our cloud providers under their SOC 2 Type II programs. TLS 1.2+ in transit. Tenant data is logically isolated and analysis runs in per-customer sandboxes.
Your data is walled off from every other customer. Analysis runs in a private sandbox and is never co-mingled across customers.
Data stored and processed in US-based infrastructure, hosted on SOC 2 Type II compliant providers.
Complete. The Type II report is available on request, and live compliance status is published at trust.kimpton.ai.
Live compliance, live controls
Our trust center publishes real-time status of our security controls, policies, and SOC 2 report. It is the single source of truth for our compliance posture, available to review any time.
Common questions
Can Kimpton trade on my behalf or transfer funds?
No. Kimpton uses read-only integration. We have zero ability to execute trades, initiate transfers, or modify your accounts in any way.
Is my data used to train AI models?
Never. We use commercial AI models with strict data processing agreements that prohibit training on customer data.
What happens if I disconnect my portfolio?
When you disconnect a portfolio, the associated holdings and transaction data are immediately deleted from our systems. Contact security@kimpton.ai if you need a full account deletion.
What is your SOC 2 status?
SOC 2 Type II is complete. The report is available on request through security@kimpton.ai, and live status is published at trust.kimpton.ai.
Security work does not finish
Security is an ongoing practice, not a finished project. We are confident in the controls we have today: read-only access, no model training, tenant isolation, and encryption everywhere. The landscape of threats keeps moving, and so do we.
SOC 2 Type II is complete, and live status is published at trust.kimpton.ai. Fine-grained access controls, audit trails, and SAML SSO are on the enterprise roadmap.
If you find something we should fix, tell us at security@kimpton.ai. For general questions, see support; for data handling, see our privacy policy. We would rather hear it from you than miss it.