Skip to main content

SECURITY & DATA

Security & Trust

KageAI is an AI assistant for authorized security assessment and remediation. This page describes the data we process, where agent code runs, and the services we rely on to operate.

Last updated

Data we process

Depending on how you use KageAI, the service processes:

  • Prompts and task messages you send to the agent
  • Files you upload (PDF, CSV, JSON, TXT, Markdown, DOC/DOCX, and PNG/JPEG/WebP/GIF images), including text extracted from them
  • URLs and search queries used when the agent browses or searches the web
  • Terminal commands and their output from agent sandbox sessions
  • Browser screenshots captured inside the agent sandbox
  • Notes and custom instructions you save
  • Account information such as your email address and name
  • Usage analytics and error diagnostics

AI model providers

Task requests are routed through OpenRouter to the provider behind the model you select, such as Anthropic, Google, DeepSeek, Moonshot AI, or xAI. Your prompt, relevant conversation context, and tool results are sent to that provider to generate a response.

When the agent searches the web or opens a URL, search queries are processed by Perplexity and page content is retrieved through Jina AI. When content moderation is configured, message content may be submitted to OpenAI for screening.

Each provider processes data under its own terms. Whether data is used for model training varies by provider, so we don't make a blanket guarantee on this point — refer to the policies of the providers listed below.

Execution environments

By default, terminal and browser actions run in an isolated E2B cloud sandbox. You can delete your sandboxes at any time from Settings → Data controls.

Local execution runs commands directly on your machine with your user's privileges and no isolation, so we recommend it only on machines dedicated to testing.

Account security

  • Authentication is handled by WorkOS AuthKit; we don't operate our own password database
  • Multi-factor authentication (TOTP) is available in Settings → Security
  • Sessions can be revoked per device or across all devices from Settings → Security

Billing

Subscription and extra-usage payments are securely processed by our authorized payment provider. KageAI does not store complete card details on its servers. Plan access is granted or revoked only from payment status verified with the provider.

Data deletion

  • Delete individual tasks, or all tasks at once
  • Delete your terminal sandboxes
  • Revoke links to tasks you have shared
  • Delete your account, which removes application database records and deletes your authentication record
  • Deleting and recreating an account does not reset usage limits or referral eligibility

Subprocessors

The following services process data on our behalf:

OpenRouter

Purpose
Routes task requests to third-party AI model providers
Data categories
Prompts, conversation context, file content, tool output

OpenAI

Purpose
Content moderation when moderation is configured
Data categories
Message content submitted for moderation

Perplexity

Purpose
Web search performed by the agent
Data categories
Search queries from agent runs

Jina AI

Purpose
Webpage content retrieval for the agent
Data categories
URLs and retrieved page content

E2B

Purpose
Cloud sandboxes
Data categories
Commands, command output, files inside the sandbox

Convex

Purpose
Primary application database
Data categories
Account data, tasks, messages, files, settings

Amazon Web Services (S3)

Purpose
File storage
Data categories
Uploaded files

Upstash / Redis

Purpose
Rate limiting and response stream resumption
Data categories
Transient identifiers and streaming state

WorkOS

Purpose
Authentication and account management
Data categories
Email, name, sessions, MFA enrollment

PostHog

Purpose
Product analytics and error tracking
Data categories
Usage events and diagnostic data

Trigger.dev

Purpose
Background execution of long-running agent tasks
Data categories
Task payloads including conversation context

Vercel

Purpose
Application hosting
Data categories
Request data processed by the web application

Responsible disclosure

KageAI does not currently publish a security-reporting contact. Do not send sensitive vulnerability details through the Help Center. A dedicated intake link will appear here after its monitoring and ownership are verified.

Incident communication

For availability updates and scheduled maintenance, check the public status page (opens in a new tab). If an incident affects your data, we notify affected users through the service.

Product transparency

KageAI's application repository is private. We document how prompts, files, subprocessors, and sandbox sessions are handled on this page and in the linked policies, and we update those disclosures when the product changes.

Compliance

KageAI doesn't currently hold SOC 2, ISO 27001, or other third-party certifications. The service is offered in beta, as described in our Privacy Policy and Terms of Service. We'll update this page as our compliance program develops.

Policies & guidance

The Help Center contains product guidance; a public security contact is coming soon.