Skip to content

Security and compliance

kOS is operated by KlusAI Labs SRL, a company registered in Cluj-Napoca, Romania. That single fact does most of the work on this page: because KlusAI is established in the EU, it is directly subject to EU data protection law, and your data does not leave EU jurisdiction.

This page summarises the commitments KlusAI publishes on its Security page, Data Processing Agreement and Privacy Policy. Those pages are the authoritative versions; if you need a signed document, ask for it rather than citing this summary.

ISO 27001. KlusAI holds ISO 27001 certification for information security management, audited annually. Certificates and audit reports are available on request as part of an audit or security review.

Native GDPR. As a Romanian company KlusAI is directly subject to the GDPR. There are no Standard Contractual Clauses or adequacy decisions to negotiate for processing that stays in the EU, and the competent supervisory authority is the Romanian data protection authority, ANSPDCP.

EU data sovereignty. All data is processed and stored within EU borders. No transatlantic transfers, and no US jurisdiction concerns — which is what removes the usual Schrems II and CLOUD Act questions from a European buyer’s evaluation.

EU AI Act. kOS is designed for the EU AI Act, with documentation, risk assessments and transparency measures for its AI systems.

For personal data you put into kOS, you are the controller and KlusAI is the processor. Concretely, under the DPA KlusAI undertakes to:

  • Process personal data only on your documented instructions.
  • Keep personnel under confidentiality obligations.
  • Implement appropriate technical and organizational security measures.
  • Assist you in responding to data-subject requests.
  • Delete or return personal data when the service agreement ends — within 30 days, at your choice, with deletion certified on request. Backups are retained no longer than 90 days.
  • Make available the information you need for a compliance audit, including ISO 27001 certificates and responses to security questionnaires. On-site audits are possible on reasonable notice.

Sub-processors. KlusAI may engage sub-processors under written contracts imposing equivalent obligations, with prior notice of new ones and an opportunity to object. KlusAI remains liable for their compliance. A current list is available on request.

Breach notification. KlusAI notifies you without undue delay, and within 48 hours where feasible, of a personal data breach, with the nature of the breach, the categories and approximate number of people affected, likely consequences, and the measures taken.

Enterprise DPAs. To execute a DPA tailored to your organization, contact KlusAI at the address published on the Security page (hello@klusai.com for the KlusAI-branded products).

The controls KlusAI publishes, grouped as its Security page groups them.

Infrastructure. EU-based cloud infrastructure carrying its own ISO 27001 certifications. All data encrypted at rest with AES-256 and in transit with TLS 1.3. Network segmentation and private networks with strict firewall rules. Regular vulnerability scanning and annual penetration testing. DDoS protection and a web application firewall.

Access control. Role-based access control on the principle of least privilege. Multi-factor authentication required for all KlusAI employees. SSO integration with enterprise identity providers over SAML and OIDC. Comprehensive audit logging of access and actions. Quarterly access reviews and immediate deprovisioning.

Data protection. Customer data isolation with logical and physical separation. Automated, encrypted backups with EU geographic redundancy. Data retention policies with secure deletion procedures. EU data residency by default. And the commitment that matters most to most buyers: customer data is never used for model training without explicit consent.

Organizational. Background checks for employees with data access. Annual security awareness training and phishing simulations. A documented incident response plan exercised regularly. Business continuity and disaster recovery plans tested annually. Ongoing security monitoring.

Because kOS is an AI product, KlusAI publishes a second set of controls aimed at the model layer:

  • Model isolation — customer-specific models are isolated and never shared; fine-tuned models are encrypted and access-controlled.
  • Input and output filtering — content moderation and safety filters.
  • Prompt injection protection — multi-layer defences against injection and jailbreak attempts.
  • Audit trails — logging of API calls, model interactions and administrative actions.
  • Data minimization — only the data necessary for service delivery is processed and retained.
  • Red team testing — regular adversarial testing of the AI systems.

If your requirement is that client material never reaches a third-party AI provider at all, that is a product choice rather than a policy one — see Privacy tiers and the KlusAI Outpost option.

Several of the commitments above have a control you operate yourself:

  • Roles and least privilege — assign the narrowest role that lets someone do their job. See Organizations, roles and modules.
  • Two-factor authentication — enable it on your own account under Account → Security, and generate backup codes.
  • Audit log — where your product includes the Organization section, Organization → Audit log records what happened in your tenant, with tabs for configuration changes, sign-in and security events, which sources the AI used, and deletions.
  • UsageOrganization → Usage, in the same section, shows your organization’s consumption.

Under the GDPR the people whose data you hold have rights of access, rectification, erasure, restriction, portability and objection, and rights concerning automated decision-making. KlusAI will assist you in responding to those requests, and responds to requests about data it holds as controller within one month.

Complaints can be lodged with a supervisory authority; for Romania that is ANSPDCP (dataprotection.ro).

Security questions, questionnaires and disclosure

Section titled “Security questions, questionnaires and disclosure”

KlusAI’s security team handles questionnaires, audits and compliance reviews at the contact address on the Security page. Security vulnerabilities should be reported to the same address.