Security & Trust

How Kela protects your data, your documents, and your deals.

SOC 2 Type I Certified

Kela has been independently assessed by a third-party auditor and meets the AICPA Trust Services Criteria for Security, Availability, and Confidentiality. Our certification demonstrates a verified commitment to protecting your data.

View Full Trust Center Start Free Trial

Trust Center includes: security controls, subprocessors, incident history, and compliance documentation.

How We Protect You

Enterprise-grade security at every layer

Kela is designed to handle the most sensitive financial and legal documents.

Encryption at Rest & In Transit

All files stored using AES-256 encryption. All data in transit is protected by TLS 1.3. Encryption keys are managed using envelope encryption with per-organization key derivation.

Access Control & MFA

Granular per-user, per-folder permissions. Google SSO and TOTP-based multi-factor authentication are available for all accounts. Admin sessions use mandatory MFA.

Immutable Audit Logs

Every action — views, downloads, logins, permission changes — is permanently logged with user identity, timestamp, and IP address. Logs are exportable as CSV at any time.

Dynamic Watermarking

Every PDF rendered inside Kela is automatically watermarked with the viewer's name and IP address. Document leaks are instantly traceable to the individual who viewed them.

DigitalOcean Infrastructure

Deployed on DigitalOcean Kubernetes behind a dedicated load balancer, with TLS certificates auto-issued and renewed via Let's Encrypt. Database is DigitalOcean Managed PostgreSQL with automated backups and point-in-time recovery.

NDA Gating & Session Controls

Require NDA acceptance before any user can access a data room. Configurable session timeouts and automatic log-outs protect access on shared or public devices.

Continuously Verified

AI accuracy, checked every night

FundOS's AI agents are graded on a fixed evaluation suite — waterfall and NAV math, documentation accuracy, and tenant isolation — with results published automatically. The figures below are a manual baseline run on 2026-07-16; the nightly unattended series begins accruing shortly.

97.5%
Documentation accuracy
78/80 tasks correct · 0 hallucinations detected
89.5%
Golden-case pass rate
17/19 scenarios passed · fund distributions, break resolution, reconciliation
Download dated eval report (PDF)
Last updated 2026-07-16T15:26:48Z
Deterministic by design

The model drafts. Code decides what ships.

Every AI output and every governed write in FundOS passes a runtime enforcement gate — pure code, zero LLM calls — evaluated against a declarative policy graph before it reaches a user or the ledger. Every evaluation writes an immutable verdict record your compliance team can export and audit.

19
governance policies
in the default graph
14
deterministic checks
(no model in the gate)
golden fixtures pinned in CI —
a weakened check fails the build
190
outputs evaluated
in the last 30 days

The policy graph is public: any AI agent can read /.well-known/governance.json before acting · policy version b88919e3f7b9c95a…

Subprocessors

We work with a limited number of vetted third-party providers. A complete and current list is always available at our Trust Center.

AWS Vercel DigitalOcean (Compute + PostgreSQL) OpenAI Stripe Google (OAuth) DocuSign

Responsible Disclosure

Found a security vulnerability in Kela? We take all reports seriously and respond within 48 hours. Please contact our security team directly — do not publish findings publicly before we've had a chance to investigate.