Security Overview
Kempian's security program at a glance — encryption, access control, tenant isolation, incident response, and responsible disclosure.
This document summarizes the security principles and controls Kempian applies to protect Platform data, for candidates, recruiters, employers, and prospective enterprise customers evaluating Kempian's Trust Center.
> *This document is part of Kempian's Trust Center documentation. It is reviewed periodically and does not constitute legal advice. Draft v0.2 — pending final legal review before publication.*
Kempian ("we," "us," "our") refers to Adept AI Inc., a Delaware corporation, principal place of business at registered address placeholder. Security is a shared responsibility across Kempian's engineering, governance, and compliance functions. Kempian maintains this overview alongside its broader Trust Center documentation as controls mature. Enterprise customers running a procurement or security review should also request the Security Overview (Detailed), which is available under confidentiality and gives fuller technical and status detail than appears here.
Encryption
Kempian encrypts personal data both at rest and in transit, consistent with standard practice for SaaS platforms handling personal and employment-related data. Kempian encrypts data in transit as it moves between a user's browser or application and the Platform, and encrypts data at rest within its infrastructure. Specific implementation detail — hosting provider, region, and key-management approach — will appear in the Security Overview (Detailed) once those details are finalized.
Access Control and Authentication
Kempian governs access to its systems, and to candidate, recruiter, and employer data, by one principle: a user should be able to see and do only what their role requires. Recruiter and employer accounts operate within role-based permissions scoped to their own organisation. Kempian similarly restricts and reviews internal access to production data and systems, and follows standard industry practice for authenticating Platform accounts that handle sensitive personal data.
A candidate's own record-level permissions are part of this same access-control model. For example, Kempian enforces which fields a Connected candidate has chosen to share, and an organisation-level setting cannot override those choices, consistent with the Candidate Privacy & Visibility Notice.
Tenant Isolation
Kempian is a multi-tenant SaaS platform. A foundational security requirement follows from that: one employer's or agency's data cannot be accessed or inferred by another tenant, including through the AI Features. Kempian treats tenant isolation as a required architectural property of the Platform, not an optional configuration, and is progressively strengthening its enforcement across every AI-assisted workflow as part of its ongoing compliance program. Enterprise customers with tenant-isolation questions relevant to their own risk assessment can raise them at trust@kempian.com.
Logging and Monitoring
Kempian logs activity across the Platform to support security monitoring, troubleshooting, and audit needs. This includes access to candidate and employer data and AI-assisted actions. Kempian logs AI-assisted decisions as part of its broader auditability commitments, described further in the AI Governance Statement. Candidates can also view their own history of consent, disclosure, and access events through the Privacy Timeline described in the Candidate Privacy & Visibility Notice. Kempian reviews logging and monitoring practices periodically as part of its ongoing compliance program.
Incident Response
Kempian maintains an internal incident response process for identifying, triaging, and responding to security incidents affecting the Platform. This process covers technical security incidents as well as AI-related incidents such as a suspected prompt-injection vulnerability or unauthorized data access. Specific response-time commitments and escalation detail are addressed with enterprise customers individually and are set out in the Security Overview (Detailed).
Backups and Business Continuity
Kempian follows standard SaaS industry practice for data backup and business continuity planning, so Platform data and service availability can be recovered if a disruption occurs. This includes routine backup of production data and a plan for restoring service if an infrastructure failure occurs. Specific backup frequency, retention, and recovery-time targets will appear in the Security Overview (Detailed) once confirmed with engineering. backup and disaster-recovery specifics placeholder.
Sub-Processor Governance
Kempian uses a limited set of third-party sub-processors to operate the Platform. These include providers that power the AI Features, plus infrastructure and operational vendors supporting hosting, communications, and analytics. Each sub-processor is subject to Kempian's data-handling requirements, covered in full in the standalone Subprocessor List. Kempian's Data Processing Agreements with sub-processors are designed to cover matters such as data use limitations and retention. Enterprise customers can request current sub-processor and Data Processing Agreement status at trust@kempian.com.
Data Residency
Kempian operates across the EU/UK, the United States, and India. Data residency and cross-border transfer practices depend on where a user and their organisation are located. Full detail on data residency, applicable transfer mechanisms, and jurisdiction-specific handling appears in the Privacy Policy. hosting region / data residency specifics placeholder.
Secure Development Practices
Kempian follows a secure software development lifecycle designed to catch security issues before they reach production, including code review and testing before release. Changes to production AI systems, including matching-model versions, are designed to go through internal review before deployment. Material changes also trigger a compliance review, as described in the AI Governance Statement. As Kempian's engineering and security programs mature, this practice continues to be formalized and documented in greater detail, consistent with the standards referenced below.
Vulnerability Management and Responsible Disclosure
Kempian welcomes responsible disclosure of security vulnerabilities, including issues affecting the AI Features such as prompt-injection weaknesses. Security researchers and users who identify a vulnerability should report it to security@kempian.com. Kempian will acknowledge good-faith reports and, where appropriate, share an update on remediation status. This mirrors the responsible-disclosure protection set out in the AI Acceptable Use Policy. A user who reports a vulnerability in good faith, without exploiting it beyond what's reasonably necessary to demonstrate it, will not be treated as having violated Kempian's policies for the act of disclosure itself.
Standards Alignment
Kempian's information-security and AI governance programs are designed with reference to the ISO/IEC 27001 (information security management) and ISO/IEC 42001 (AI management systems) frameworks. Kempian has not completed independent certification against either standard. Alignment with their control structures is part of Kempian's ongoing compliance roadmap, and this page will be updated as certification milestones are reached.
Health Data and HIPAA
Kempian serves customers across many sectors, including healthcare. It processes occupational and professional-qualification data — for example, clinical licence and certification numbers — where relevant to a candidate's profile. This is occupational-qualification data, not protected health information (PHI), and Kempian treats it accordingly under its data classification. As a matter of ordinary product function, Kempian does not process PHI, and is not, by default, a HIPAA business associate for its healthcare-sector customers. A specific enterprise engagement that would involve PHI requires a separate written arrangement with Kempian before any such data is processed.
Related Documents
This overview should be read together with: the AI Governance Statement, the Security Overview (Detailed), the Subprocessor List, the Privacy Policy, the AI Acceptable Use Policy, and the Data Processing Addendum.
Contact
- Security vulnerability reports / responsible disclosure: security@kempian.com
- Enterprise due-diligence, procurement, and Trust Center inquiries: trust@kempian.com
- Privacy questions: privacy@kempian.com
Kempian — Security Overview — v0.3 (Draft) — July 2026