Security & trust
Built to be trusted with your telemetry
Ketl connects read-only to the signals you already collect and uses them to answer your incidents only. Your data never trains a shared model, and you keep full control over retention, routing, and access.
Your telemetry, your incidents, full stop
The core rules that govern how Ketl handles what you connect.
Read-only connections by default. Ketl never writes to or triggers actions on your systems.
Your telemetry answers your incidents only, and is never used to train or update a shared model.
Encryption in transit on all connections (TLS 1.2 minimum, TLS 1.3 preferred).
Encryption at rest for all stored telemetry and derived data.
Configurable retention windows. The default is short, and you can reduce it further.
Deletion on request, processed within 30 days.
Read-only by design
Every integration Ketl ships has a read-only access mode as the default. We pull the log and trace window around an alert, correlate recent deploys, and reference past incidents. We never push to your services, create or modify data, or run actions without an explicit human command.
Telemetry is processed in-context during a diagnosis and is not used to improve or update any shared model. Your production data stays yours.
The right people, with the least-privilege access
SSO and SCIM
SAML 2.0 single sign-on and SCIM automated provisioning are available on the Scale plan, so your identity provider remains the source of truth for who has access.
Role-based access
Three roles per workspace: viewer (read diagnoses), operator (trigger and annotate), and admin (manage sources and members). Roles apply to data and actions, not just the UI.
Audit log
Every workspace action is logged: who triggered a diagnosis, who viewed the result, who modified a connected source. The log is available to admins and exportable on request.
API token scoping
API tokens are scoped to a single workspace and carry the least-privilege role needed. Tokens can be rotated or revoked at any time without a support ticket.
Stay inside your perimeter
On the Scale plan, you control where your telemetry goes and which models touch it.
Self-host or run in your VPC
Scale customers can deploy the Ketl service inside their own cloud environment or virtual private cloud. Telemetry never leaves your perimeter. We provide a container image, Terraform modules, and a security review to support procurement requirements.
Model-agnostic routing
Ketl routes each inference step across frontier and open-weight models, selecting for quality and cost at each step. Scale customers can pin specific providers, exclude external providers entirely, or route all inferences to open-weight models they host themselves, keeping telemetry within their own boundary.
Who touches your data, and why
We keep the list short and honest. Scale customers can remove model providers from this list by routing to open-weight models they self-host.
Cloud infrastructure
Amazon Web Services (us-east-1)
Compute, storage, and networking for the hosted Ketl service. Logs and derived data are stored here unless you self-host.
Model providers
Multiple providers, model-agnostic
Language model inference for diagnosis steps. Scale customers can pin specific providers, exclude external providers entirely, and route all inferences to open-weight models they self-host.
What is done and what is in progress
We report our posture honestly. A label that says in progress means exactly that.
SOC 2 Type II
In progressOur audit period is underway. The report will be available to Scale customers under NDA once complete. We are happy to answer specific control questions during sales.
GDPR
ReadyA data processing agreement (DPA) is available on request. EU data residency controls and sub-processor documentation are available to Scale customers.
CCPA
ReadyData subject rights requests are handled at privacy@getketl.com within 30 calendar days. We do not sell personal data.
Report a vulnerability
If you find a security issue in Ketl, please report it to security@getketl.com. We acknowledge every report within one business day and coordinate disclosure with you before going public. We do not pursue legal action against researchers who act in good faith and follow this process.
- Email a clear description of the issue and the steps to reproduce it.
- Give us reasonable time to investigate and patch before publishing your findings.
- Avoid accessing data that belongs to other customers.
- Do not run automated scanners against production endpoints.
Questions about security or data practices: email security@getketl.com. See also the Privacy policy and How the AI works.