Skip to main content

Trust centre

How Kemble handles your data, what we can see, and what we have not finished.

Data we hold

Account details, the organizations you belong to, the messages and files you send, and operational records: audit rows, sessions, and usage counters for the limits your plan enforces.

Message content is stored so it can be searched and read back. It is not used to train any model.

Who can see it

Within your organization, visibility follows the permission model: private channels are visible to their members, and the check runs inside the query rather than filtering results afterwards.

Kemble staff do not read customer message content as a matter of routine. There is no cross-tenant content moderation surface, and the platform console deliberately does not have one — building it would need a reason-and-log discipline that has not been designed yet.

Encryption

In transit, HTTPS. At rest, the storage provider’s encryption. Passwords are hashed with Argon2 and are not recoverable.

Sub-processors

Kemble uses a small number of third parties: object storage for uploads, an SMTP provider for transactional email, a media server for large voice rooms, and an AI provider for K Buddy. The current list is available on request and before any contract is signed.

Reporting a vulnerability

Email security@kemble.io. We will acknowledge within two working days. Please give us a reasonable window to fix an issue before disclosing it, and we will credit you unless you would rather we did not.