Trust centre

Security evidence, before you have to ask for it.

Most of what a security review needs is on this page. Where a document is confidential, request it and we will send it under NDA — usually the same working day.

All services operational

The short version

The architecture is the control

K-Lake is software you run. That single fact removes most of the questions a vendor security review is designed to answer.

Why the scope of review is smaller than you expect

K-Lake is deployed on your infrastructure. In normal operation we do not receive, store or process your document data, which typically narrows a vendor assessment considerably compared with a cloud service that holds a copy of your estate.

The document estate, the index and permission enforcement all remain inside your perimeter. Where you choose to connect a cloud model, only the specific retrieved, permission-checked snippet is sent, under your own agreement with that model vendor. Where you require full isolation, K-Lake runs against a local model with no external egress at all.

Licensing is enforced offline. There is no licence-server call-home, and no telemetry leaves your environment — metrics and logs are exposed for your own monitoring stack rather than sent to us. That is what makes air-gapped deployment possible rather than theoretical.

Security

Controls you can inspect

Permission-aware retrieval enforced at query time against your existing identity provider, and enforced in the database by row-level security rather than in application code — so access is denied by default and new code paths inherit the control automatically. Strict tenant isolation at the same layer. The core services and every connector are written in Rust, which removes memory-corruption vulnerability classes by construction. Every answer carries a citation, so any output can be checked against its source.

Privacy

Data residency by design

Your data does not leave your environment, so residency is a property of where you deploy rather than a contractual promise about where we store things. Aligned to UK GDPR and GDPR.

Compliance

Built for regulated review

Designed for organisations subject to DORA, FCA rules, NHS data governance, HIPAA and public-sector data policy. Our certification roadmap is published below rather than implied.

Certifications and assurance

Where we are, stated plainly

We publish status honestly, including what is not yet in place. A vendor who implies more than they hold is a risk in itself.

ItemDetailStatus
ISO 27001Information security management system covering the Zegress.Ai corporate environment.In progress
SOC 2 Type IIIndependent report on security, availability and confidentiality controls.Roadmap
Cyber Essentials PlusUK government-backed assurance of baseline technical controls.In progress
Independent penetration testThird-party application and infrastructure test; summary report available under NDA.In progress
UK GDPR and GDPR alignmentData protection policy, records of processing, and a standard data processing agreement.Available
Air-gapped operationDemonstrated answering questions with the internet physically disconnected.Demonstrated
Offline licensingNo licence-server call-home; no telemetry leaves your environment. Verifiable at the network layer.Available
Vulnerability disclosureResponsible disclosure policy and a security contact for researchers.Available

Status is reviewed monthly. If a certification matters to your procurement timeline, tell us which one and when you need it, and we will tell you honestly whether we can meet that date.

Documentation

What we can send you today

Public documents download immediately. Confidential documents are released under NDA, normally within one working day.

Security overview

Architecture, data flow and control summary for a security reviewer.

Public

Data processing agreement

Standard DPA covering our limited role as a processor.

Public

Deployment and hardening guide

Reference architecture, network requirements and hardening steps.

Public

Benchmark methodology

How the retrieval-quality and FinanceBench figures were produced.

On request

Penetration test summary

Third-party test findings and remediation status.

Under NDA

Business continuity summary

Continuity, escalation and support-failover arrangements.

Under NDA

Request documents Or email [email protected] Support and service levels

Sub-processors

Who touches what

Because K-Lake runs on your infrastructure, the sub-processor list for the product itself is short. These are the parties involved in running our business, not in processing your documents.

PartyPurposeCustomer document data
MicrosoftAzure Marketplace transaction, billing and co-sellNo access
Your chosen model vendorOnly where you connect a cloud model, under your own agreementRetrieved snippet only, at your election
Zegress supportSupport engagement, only when you open a ticket and grant accessOnly what you share in a ticket

We publish changes to this list before they take effect. To be notified, email [email protected].

Reporting a vulnerability

If you have found something, tell us

We welcome reports from security researchers and will not pursue action against anyone acting in good faith under this policy.

Responsible disclosure

Email [email protected] with enough detail to reproduce the issue. We acknowledge within one working day and aim to give you an assessment within five.

Please do not access, modify or exfiltrate data belonging to anyone else, and give us reasonable time to remediate before publishing. We will credit you when a fix ships, unless you prefer otherwise.