Security

Your keys, your cloud,
your code.

Security at Kitted starts with the architecture, not a policy page. Every tool runs fully sandboxed, isolated from every other, and stays as readable code that's yours to keep. Here's how we think about protecting your work and your data.

How it's built

Safe by default.

The safe path is the default path, built into how every tool runs and where your data lives.

Sandboxed tools

Every tool runs in its own sandbox. It can't see, reach, or be reached by any other tool in your workspace. Isolation is the default, not a setting you have to remember to turn on.

Real, readable code

Every tool is an ordinary script you can open, read, and take with you. There's no black box, and nothing is hidden or compiled away. The code you run is the code you can review.

Credentials stay out of the AI's reach

API keys and tokens are encrypted at rest with AES-256-GCM, decrypted and injected only at the moment a tool runs, and never written into the model's prompt. It's enforced by the architecture, not just a policy.

We don't train on your data

We don't sell your content, and we never use it to train models, ours or anyone else's. Your work stays yours.

Deploy in your own cloud

Need Kitted inside your own environment? We can deploy it into your own VPC on AWS, Azure, GCP, or any other cloud you run, so your data and tools never leave your account. Available on request.

Where the lines are

What we always do, and never do.

We always

  • Isolate every tool in its own sandbox.
  • Keep every tool as real code you can read.
  • Keep your tools portable, yours to export and run anywhere.
  • Tell you exactly what's shipped today and what's still in progress.

We never

  • Put your API keys or tokens into the AI model's prompt.
  • Use your data to train our own or any third-party model.
  • Hide what a tool does behind a black box.
  • Lock you into a runtime you can't leave.
  • Claim a certification we don't actually hold.
FAQ

Questions your security team asks.

The short answers. For anything specific to your review, the founder is one email away.

Can one tool see or reach another tool's data?

No. Every tool runs in its own sandbox, isolated from the others in your workspace. One tool can't see, reach, or be reached by another.

Where are my API keys and credentials stored?

Encrypted at rest with AES-256-GCM, decrypted and injected only at the moment a tool runs, and never written into the AI model's prompt. Credentials live in the environment, not in the code you can download.

Do you train AI models on my data?

No. We don't sell your content, and we never use it to train models, ours or any third party's. Your work stays yours.

Can I run Kitted in my own cloud?

Yes, on request. We can deploy Kitted into your own VPC on AWS, Azure, GCP, or any other cloud you run, so your data and tools never leave your account.

What happens to my tools if I stop using Kitted?

They're real, portable code. Every tool is an ordinary script you can export and run anywhere, with no runtime lock-in. Leaving Kitted doesn't strand your work.

How do I get answers for my security review?

Talk straight to the founder. Bring your team's questions and requirements, and you'll get direct answers, no sales layer in between.

Talk to a human

Bring Kitted to your
security review.

Security is a conversation, not a checkbox. Bring your team's questions and requirements straight to the founder, no sales layer in between.

Konrad DębiecFounder
Talk to the founderFound a security issue? Email hello@kitted.dev.