Quick answers for procurement
For an initial security and compliance evaluation — current state, stated plainly:- Primary infrastructure and data storage and processing run in the European Union. The app runs on Fly.io in Frankfurt (
fra); data lives in AWSeu-central-1(databases, files, queues) and Pineconeeu-central-1(vector index). Meeting audio capture and transcription (Recall.ai,eu-central-1) and product analytics (PostHog EU cloud) also run in the EU. Transitional note: frozen US backups are scheduled for deletion by 2026-08-16. - What still processes in the US: LLM inference (OpenAI, Anthropic) under their commercial API terms, and transactional email (Resend) — see the sub-processor table below.
- Retention and deletion: one policy per data type in the section below. The short version: meeting audio expires on its own (7 days at the provider); everything else is kept until you delete it, and deletion is real — cascading to facts, embeddings, files and the provider’s copy, out of backups within 35 days at most.
- Recording consent documented — see Recording policy.
- DPA: in preparation — email legal@kb2b.app for status and timeline.
- Security call with a responsible party — request one by emailing legal@kb2b.app with subject “Security call”.
Retention and deletion
One policy, per data type. “Delete” means actually delete: the data leaves primary storage immediately and leaves backups by natural expiry, within 35 days at most.
Operational detail on meeting deletion in the Recording policy.
If you need more detail
Current sub-processors
All customer data flows go through the services below. The AI providers (OpenAI, Anthropic) do not train models on data sent through their APIs, per their commercial API terms; they may retain inputs briefly for abuse monitoring.
Sign-in uses Google or GitHub as OAuth identity providers (basic profile only).
Workspace isolation
Each kb2b workspace lives in its own POT (Knowledge Pot — the account’s knowledge container). POTs are isolated at the database level byworkspace_id. There is no way for one workspace to query another workspace’s data — neither accidentally, nor via prompt injection.
Security contacts
- General: legal@kb2b.app
- Vulnerability disclosure: security@kb2b.app

