Security
Your data trains your model. No one else's.
Kethra is built on one rule: your data trains your model only, and your weights are yours. This page covers how we handle data, where weights live, how access is controlled, and where our compliance posture stands today.
Encrypted, isolated, yours
Your data does not train the shared base and it does not train another customer's model. That rule holds at every layer of the pipeline.
TLS 1.3 everywhere
All data moving between your systems and ours travels over TLS 1.3. There is no unencrypted path into the pipeline.
AES-256 at rest
Your corpus, your eval data and your tailored weights are encrypted at rest with AES-256 across all storage layers.
Your data only
Your data trains your model only. It is never used to train the shared base or another customer's fine-tune. This is a contractual commitment, not a product setting.
Deleted on request
Request deletion and we remove your raw training data from our systems within 30 days. Written confirmation is provided on completion.
A written Data Processing Agreement is available to all customers and is required for regulated industries. It covers what we process, on what lawful basis, and what you may request. Write to support@basisresearch.tech to request a copy.
Where your model lives
Your tailored weights are your property. Where they live is your decision, and we provide the tooling to move them into whichever configuration your security team requires.
Kethra-managed infrastructure
By default, tailored weights are stored and served on Kethra infrastructure in the United States. Tenancy is isolated: your model is never co-located with or accessible alongside another customer's. You may export the weights at any time in a standard format.
Your own cloud or VPC
On the Atelier and Enterprise tiers, weights may be deployed directly into your own cloud account or virtual private cloud. Kethra provides the deployment tooling and a private-endpoint configuration. Once deployed, the weights do not leave your environment unless you move them.
Fully on-premises (Enterprise)
Enterprise customers may run training and deployment entirely within their own perimeter. In this configuration, no model data, training material or eval output crosses Kethra systems. We send engineers to assist the initial setup and each subsequent refinement cycle.
Least privilege, by design
Per-customer isolation
Training runs, model storage and deployed endpoints are isolated at the infrastructure level. No engineer has standing read access to customer data.
SSO on Enterprise
Enterprise customers can enforce SAML 2.0 or OIDC single sign-on across the console. Provisioning is driven by your identity provider.
Audit logging
Every access event against your training data, weights and endpoint is recorded in a tamper-evident log. Enterprise customers may export logs to their own SIEM.
Least privilege
Elevated access to customer data requires an explicit, time-bounded grant, approved by a second party and reviewed on completion.
Key management
Encryption keys are managed per-customer. Enterprise customers may bring their own key via their cloud KMS so Kethra holds no decryption material.
Report a vulnerability
Responsible disclosure is welcome at security@basisresearch.tech. We acknowledge within one business day and resolve confirmed issues within 90 days, with 30-day progress updates.
Where we stand
We state our compliance position as it is, not as we would like it to appear. Where something is in progress, we say so.
SOC 2 Type II
Our SOC 2 Type II audit is in progress with an accredited third-party auditor. We expect to share the completed report with customers once it is issued. Customers who need current controls documentation in the meantime may request it from support@basisresearch.tech.
GDPR
Kethra's data handling is designed to be aligned with the EU and UK GDPR and the California Consumer Privacy Act (CCPA/CPRA). We process personal data only where we have a lawful basis, and our DPA documents that basis for each processing activity. Where your corpus contains personal data, Kethra acts as processor and you remain the controller.
Data residency
Training data and weights are stored by default in the United States. EU and UK data residency are available on request for all paid tiers. Specific-region requirements can be accommodated within the Enterprise configuration.
Sub-processors
We use a small number of sub-processors for compute, object storage and communications. Enterprise customers may request the current list and will receive advance notice of any changes. Each sub-processor is assessed against our data handling standards before use.
Common questions
Own it, keep it private.
A private model on infrastructure you choose. Your data trains your model only, and your weights are yours to keep.