Organizations entrust Kindred with their most important relationships — students, alumni, and communities. Protecting participant data isn't a feature. It's the foundation of everything we build.
Kindred never stores call audio. Voice streams from the participant's browser to our voice provider (ElevenLabs) over encrypted WebRTC, processed in real time with audio recording disabled — no recordings are retained.
Call audio is never recorded. The text transcript and AI-generated insights from each conversation are retained per organization, encrypted in transit and at rest, and deletable on request.
Sign in via SSO with major identity providers or secure magic-link email — no passwords to leak or phish, no self-registration. Accounts are provisioned by administrators only.
Every call requires explicit opt-in. Consent events are recorded with full forensic detail: text snapshot, hash, timestamp, and user agent.
Your data, your conversations, your control. Here's exactly how we handle AI processing.
Organizations don't just adopt Kindred for themselves — they adopt it on behalf of their networks. We take that responsibility seriously.
Participants are clearly informed that their conversation is AI-powered before every call begins. No hidden automation.
A quick overview so the security controls make sense.
An org admin creates a campaign, uploads a member list (typically name and email; organizations may include additional context fields), and generates unique call links.
Before any call begins, the participant sees a consent screen and must explicitly opt in. Consent is recorded with a full audit trail.
The participant has a conversation with an AI voice agent directly in their browser. Audio streams directly between the browser and ElevenLabs via WebRTC — Kindred's servers never see or store audio.
A text transcript is generated from the conversation. AI-generated insights are extracted and retained for the organization.
Admins view aggregated insights and analytics. They never hear the original audio.
With organizer approval, Kindred can suggest connections between participants based on their conversations and introduce them by email. Organizations can require both participants to confirm before an introduction is made.
Coming soon: Formal FERPA compliance documentation and institutional agreements
Coming soon: GDPR-compliant data residency options and consent withdrawal workflow
We are actively preparing for SOC 2 Type II certification. Our current practices align with SOC 2 trust service criteria, and we are formalizing policies and controls for audit readiness.
Coming soon: Application-level AES-256 encryption for sensitive fields
Coming soon: MFA enforcement for all org admins
Coming soon: Rate limiting on all public-facing endpoints
We're transparent about every third-party service that touches your data.
| Vendor | Purpose | Data Shared | Location | Their Compliance |
|---|---|---|---|---|
| OpenAI | Insight generation & AI matching | Transcript text, member profile data | US | SOC 2 Type II |
| Clerk | Authentication & SSO | Email, name, auth tokens | US | SOC 2 Type II, GDPR |
| Vercel | Frontend hosting | Static assets only (no PII) | US | SOC 2 Type II, ISO 27001 |
| Render | Backend & database | All application data (encrypted at rest) | US | SOC 2 Type II |
| ElevenLabs | Voice AI | Voice audio (recordings disabled), conversation transcript text | US | SOC 2 Type II |
| Anthropic | AI matching & insights | Transcript text, member profile data | US | SOC 2 Type II |
| Resend | Transactional email | Email addresses, notification content | US | SOC 2 Type II |
| Salesforce | CRM sync (optional, when connected by an org) | Member contact details & call activity | US | SOC 2 Type II, ISO 27001 |
No. Audio streams between the participant's browser and our voice provider (ElevenLabs) via encrypted WebRTC and is processed in real time with audio recording disabled. Kindred never stores call audio.
Call audio is never recorded. We retain the text transcript and the AI-generated insights from each conversation, encrypted in transit and at rest. Participants and organizations can request deletion at any time.
No. Kindred uses strict organization-level data isolation. Every API request validates that the requesting user is an authorized member of the relevant organization.
No. We use OpenAI, Anthropic, and ElevenLabs through their commercial APIs. Per each provider's terms, data submitted through the API is not used to train their models.
At minimum: name and email (provided by the organization), consent records, the conversation transcript, and AI-generated insights. Organizations may choose to upload additional context fields. We actively minimize collection of sensitive categories of information.
Only when an organization uses Kindred to suggest introductions. In that case an organizer may introduce you to another participant using a short summary based on your conversation, and organizations can require both people to confirm before connecting. Otherwise, your information is visible only to authorized admins at your organization.
Yes. We are happy to work with institutions on Data Processing Agreements, BAAs, and other institutional agreements. Contact us at trust@projectkindred.co.
We can provide additional security documentation, complete security questionnaires, or schedule a call with our team.
trust@projectkindred.co