Trust Center

Is it safe to connect Kipper to your accounting data?

Yes. Kipper only reads your finance data, it never writes to it. Every query is encrypted in transit, scoped to what your admins allow, and logged for a full audit trail. This page explains exactly how, with links to the agreements that make it binding.

read-only encrypted audit-logged US-hosted by default no model training

Read-only architecture

Kipper does not write to, modify, or delete data in your connected finance system. It only reads what's needed to answer a question, which is what makes it safe to open to your whole team.

Encryption in transit

Within Kipper-controlled infrastructure, data is encrypted in transit and at rest where practicable. Data delivered through a third-party channel you configure, such as SMS, Slack, or Microsoft Teams, is subject to that provider's own protections.

Access control and permissions

Admins configure exactly what each user, team, or channel can see inside the Kipper portal. Access is enforced on every question, no matter how it's phrased.

Audit logging

Every question submitted through Kipper, and the answer it gets, is logged for security, audit, and service-improvement purposes, giving admins a full record of who asked what.

AI processing, no model training

Natural-language queries are interpreted using LLMs running through AWS-managed Amazon Bedrock, inside Kipper's own AWS account, not a separate third-party AI vendor. Under AWS's published Bedrock documentation, Bedrock by default does not store your inputs or outputs, does not share them with the model providers it hosts, and does not use them to train any model. For certain models, AWS may retain inputs and outputs for up to 30 days solely for automated abuse detection, which stays within AWS and is not shared with model providers. Kipper does not use your data to train AI models.

Sub-processors

Every third party that helps operate the Service is named on a single published page, with what it does, what data it touches, and where. That page is the source of truth, not a marketing summary.

View sub-processors

GDPR and your data rights

Kipper processes your finance data as a processor acting on your instructions, under a signed Data Processing Agreement available to every customer. EU/UK GDPR rights and international-transfer handling are set out in our Privacy Policy.

Read the Privacy Policy

Data retention and deletion

Data tied to a canceled account, a disconnected finance system, or an expired trial is deleted within a reasonable period, subject to legal, security, and audit retention requirements. Kipper's copy of your data is a working copy for answering questions, never your authoritative books and records, which stay in your connected system.

Certifications

Kipper has not completed SOC 2 certification. We would rather say that plainly than overstate our compliance posture. What is true today is above: read-only architecture, encryption in transit and at rest where practicable, audit logging on every query, and US-based hosting by default. If a security review needs a specific attestation or a completed questionnaire, get in touch and we'll work through it directly.

FAQ

Security questions, answered directly

The questions we hear most before someone connects their books to Kipper.

Yes. Kipper is read-only by architecture, meaning it can never write to, modify, or delete data in your connected finance system. It only reads what's needed to answer a question, and every question is scoped to what your admins allow and logged for an audit trail.
Not yet. We don't claim a certification we don't have. What is true today: Kipper is read-only, encrypts data in transit and at rest where practicable, logs every query for audit purposes, and hosts data on AWS in the United States by default. If your security review needs a specific attestation or a completed questionnaire, contact us and we'll work through it directly.
No. Kipper's natural-language processing runs through AWS-managed Amazon Bedrock inside Kipper's own AWS account, not a separate third-party AI vendor. Under AWS's published Bedrock documentation, Bedrock by default does not store your inputs or outputs, does not share them with the model providers it hosts, and does not use them to train any model. For certain models, AWS may retain inputs and outputs for up to 30 days solely for automated abuse detection, which stays within AWS and is not shared with model providers. Kipper does not use your data to train AI models either.
Whoever your admins allow. Access is configured in the Kipper portal by team, account, or role, and it's enforced on every question no matter how it's phrased. Nobody gets more visibility than your configuration grants.
Data tied to a canceled account, a disconnected finance system, or an expired trial is deleted within a reasonable period, subject to legal, security, and audit retention requirements. Kipper's copy of your data is a working copy for answering questions, never your authoritative books and records, which stay in your connected system.
On AWS infrastructure in the United States by default. Third parties that help operate the Service are all named, with what they do and what data they touch, on our published sub-processors page, so nothing is left off that list.
Yes. Kipper processes your finance data as a processor acting on your instructions, under a Data Processing Agreement available to every customer. EU/UK GDPR rights and international-transfer details are covered in our Privacy Policy, linked below.

The documents behind this page

This page summarizes what's already binding in our legal agreements. If a claim above and a document below ever seem to disagree, the document governs.