Organizations entrust Kindred with their most important relationships — students, alumni, and communities. Protecting participant data isn't a feature. It's the foundation of everything we build.
Kindred never records, stores, or has access to call audio. Voice streams directly between the browser and OpenAI via encrypted WebRTC.
Only AI-generated insights are retained. Raw transcripts are not stored long-term — we keep only what's needed.
Sign in via SSO with major identity providers or secure magic-link email — no passwords to leak or phish, no self-registration. Accounts are provisioned by administrators only.
Every call requires explicit opt-in. Consent events are recorded with full forensic detail: text snapshot, hash, timestamp, and user agent.
Your data, your conversations, your control. Here's exactly how we handle AI processing.
Organizations don't just adopt Kindred for themselves — they adopt it on behalf of their networks. We take that responsibility seriously.
Participants are clearly informed that their conversation is AI-powered before every call begins. No hidden automation.
A quick overview so the security controls make sense.
An org admin creates a campaign, uploads a member list (name and email only), and generates unique call links.
Before any call begins, the participant sees a consent screen and must explicitly opt in. Consent is recorded with a full audit trail.
The participant has a conversation with an AI voice agent directly in their browser. Audio streams directly between the browser and OpenAI via WebRTC — Kindred's servers never see or store audio.
A text transcript is generated from the conversation. AI-generated insights are extracted and retained for the organization.
Admins view aggregated insights and analytics. They never hear the original audio.
Coming soon: Formal FERPA compliance documentation and institutional agreements
Coming soon: GDPR-compliant data residency options and consent withdrawal workflow
We are actively preparing for SOC 2 Type II certification. Our current practices align with SOC 2 trust service criteria, and we are formalizing policies and controls for audit readiness.
Coming soon: Application-level AES-256 encryption for sensitive fields
Coming soon: MFA enforcement for all org admins
Coming soon: Rate limiting on all public-facing endpoints
We're transparent about every third-party service that touches your data.
| Vendor | Purpose | Data Shared | Location | Their Compliance |
|---|---|---|---|---|
| OpenAI | Voice AI & insight generation | Voice audio (ephemeral), transcript text | US | SOC 2 Type II |
| Clerk | Authentication & SSO | Email, name, auth tokens | US | SOC 2 Type II, GDPR |
| Vercel | Frontend hosting | Static assets only (no PII) | US | SOC 2 Type II, ISO 27001 |
| Render | Backend & database | All application data (encrypted at rest) | US | SOC 2 Type II |
| ElevenLabs | Voice AI | Voice audio (ephemeral) | US | SOC 2 Type II |
| SendGrid | Transactional email | Email addresses, notification content | US | SOC 2 Type II, ISO 27001 |
We are continuously improving our security posture.
Formal audit and certification for enterprise readiness
Institutional agreements and formal compliance documentation
Third-party penetration testing and vulnerability assessment
Configurable data residency for institutions with geographic requirements
No. Audio streams directly between the participant's browser and OpenAI via encrypted WebRTC. Kindred's servers never see, process, or store audio data.
Only AI-generated insights are retained for the organization. These insights do not contain raw transcript text or verbatim participant responses.
No. Kindred uses strict organization-level data isolation. Every API request validates that the requesting user is an authorized member of the relevant organization.
No. Per OpenAI's API data usage policy, data submitted through the API is not used to train their models.
The minimum necessary: name and email (provided by the organization), consent records, and AI-generated insights. We do not collect phone numbers, SSNs, grades, or financial information.
Yes. We are happy to work with institutions on Data Processing Agreements, BAAs, and other institutional agreements. Contact us at trust@projectkindred.co.
We can provide additional security documentation, complete security questionnaires, or schedule a call with our team.
trust@projectkindred.co