Security

Security & Compliance

Keeping our clients' data secure is an absolute top priority at Klipy. Our goal is to provide a secure environment, while also being mindful of application performance and the overall user experience.

End-to-End Security

Klipy is hosted entirely on Amazon Web Services (AWS), providing end-to-end security and privacy features built in. Our team takes additional proactive measures to ensure a secure infrastructure environment. For additional, more specific details regarding AWS security, please refer to https://aws.amazon.com/security/.

Encryption

All customer data are encrypted at rest using industry-standard AES-256 encryption, and all data in transit, both internally and externally, are encrypted using standard algorithms such as TLS 1.2 and SSH.

Additionally, customer data provided for Retrieval-Augmented-Generatation (RAG) inside Klipy are encrypted with random and unique credentials for each users that are not accessible by public nor Klipy's internal team to decrypt.

Model Security

Klipy uses hosted Large Language Model (LLM) services from OpenAI and Microsoft Azure OpenAI Services. These services are secured with industry standards such as AES-256, TLS 1.2+ for data encryption at rest and in transit, and deployed on industry degree infrastructure dedicated for the services.

Also, all inputs and outputs of the model services are not used for training. For additional, more specific details regarding Enterprise privacy of OpenAI services, please refer to below materials:



Enterprise privacy at OpenAI

OpenAI Security Portal

Azure OpenAI Security

Vulnerability Disclosure Policy

Vulnerability Disclosure Policy

If you believe you've discovered a bug in Klipy's security, please get in touch at security@klipy.ai and we'll get back to you within 24 hours. We request that you not publicly disclose the issue until we have had a chance to address it.