Trust, published like a changelog.
Here's exactly what protects your data in Kommit today, and what we're still building. This page changes when the product does, not before it. If a control isn't live yet, we say so.
What's live, and what's still in build.
One control is live today. Three are in build. We publish this like a changelog: the day something ships, it moves up to live. Nothing here is a promise about the future.
Run logging
Every workflow run is recorded, with a tamper-evident trail you can export for review. This covers workflow runs. It doesn't extend to chat or other agent surfaces yet, and we won't say it does until it's true.
PII redaction
Stripping personal data out of a request before it reaches a model. This is in build. Until it ships, treat model calls as if a US sub-processor can see the input.
Enforced retention
Setting how long run data is kept and having Kommit delete it on a schedule. In build. Today we keep logs until you ask us to remove them.
EU data residency
Processing and storing your data inside the EU. In build. Today model calls run in the US, under the terms in the residency section below.
Where your data is processed today.
Right now, model calls, embeddings, and file storage are processed in the US by our sub-processors, under standard contractual clauses. EU in-region processing is in build, and this page updates the day it ships.
You can see the full sub-processor list, and our standard data processing agreement sets out the legal basis for these transfers.
No badges we haven't earned.
You won't find compliance logos on this page, and we're not going to imply Kommit meets a standard it doesn't. What we'll give your security team instead is the logging, the controls, and the documentation your own audits and DPAs need. When a control ships, it lands here first.
See it on your stack.
30 minutes with our team. We'll walk you through governance, audit, evals — and answer everything procurement will ask. Bring your own NDA; we'll sign in 24 hours.