Trust and security
How we protect your data.
Kyndrify handles your face and voice, so the details matter. This is a plain account of the controls available today and the limits you should know about.
Private media linksWorkspace-scoped accessAuthenticator-app MFASelf-serve deletionConsent records
Private media and Workspace boundaries
- Private links. Uploaded photos, voice recordings, and finished media use short-lived access links when they are shown in the Studio.
- Workspace checks. Private routes check Workspace membership and ownership before they return or change customer data.
- Separate environments. Production runs in its own deployment, with access controlled through managed service identities and secrets.
Account safeguards
- Strong passwords. Passwords need at least 12 characters and a mix of character types. They are stored as one-way hashes, never as readable text.
- Multi-factor authentication. You can enable authenticator-app MFA and backup codes from Security settings. Sensitive operator actions require a fresh MFA check.
- Login records. Attempts against an existing account are rate-limited and recorded in login history so suspicious activity is easier to spot.
Data lifecycle
- Delete individual items. You can remove Digital Twins, Avatars, voices, and eligible standalone Renders from the Studio. Some items use a recovery window before their final purge.
- Delete your profile. Self-serve profile deletion removes your user record and any solely-owned Workspace records. Shared Workspaces need an ownership transfer first so another member's work is not erased.
- Limited legal retention. Consent evidence may be retained when required to establish or defend legal rights. The privacy and biometric notices explain those exceptions.
Monitoring and response
- Operational monitoring. Application and worker health, errors, and stuck jobs are monitored. Recovery jobs handle several retry, refund, and cleanup paths.
- Workspace audit history. Membership, role, and selected billing-control changes leave an audit record for Workspace owners and operators.
- Security reports. Reports are reviewed directly. We do not publish a response-time or uptime guarantee until the matching operational process is live and measured.
AI data use and output safeguards
- No Kyndrify model training. Kyndrify does not use your photos, voice, scripts, or finished media to train a Kyndrify model. Content is sent only to services needed to complete the work you requested.
- Disclosure status. Machine-verifiable disclosure and provenance are launch requirements, but they are not yet guaranteed on every output.
- Not for protected health information. Kyndrify is not HIPAA-eligible. Do not upload protected health information or use the Studio for patient-data workflows.
Found something?
Report a security issue.
Send the details to hello@kyndrify.com. We review security reports directly and will follow up when more information is needed.
Keep your Studio protected.
Turn on MFA in Security settings, review your login history, and keep Workspace access limited to the people who need it.