Trust CenterPart of the Cast AI Group

    Security you can verify.

    Kimchi is part of the Cast AI Group. We run on the same security program, certifications and controls as Cast AI, applied to an AI coding platform where your code and prompts stay inside a boundary you define.

    Compliance

    Certifications and attestations.

    Compliance is maintained at the Cast AI Group level and covers the Kimchi platform. Reports and evidence are available under NDA through the Cast AI Trust Center.

    SOC 2
    SOC 2 Type II

    Independently audited controls for security and availability.

    ISO
    ISO 27001

    Certified information security management system.

    PCI
    PCI DSS AOC

    Attestation of Compliance on file for card data handling.

    HIPAA
    HIPAA-ready

    HIPAA-ready architecture. BAA available on request.

    Controls

    How the program is enforced.

    Controls are monitored continuously across infrastructure, people, product and process - not reviewed once a year.

    Infrastructure security

    • Data encrypted in transit (TLS 1.2+) and at rest
    • Network segmentation and least-privilege service roles
    • Continuous infrastructure monitoring and alerting
    • Self-Hosted mode runs entirely inside your own VPC

    Organizational security

    • Background checks for personnel where permitted by law
    • Mandatory security awareness training
    • Role-based access with SSO/SAML/OIDC and MFA
    • Documented onboarding and offboarding procedures

    Product security

    • Per-request audit trail for prompts, completions and tool calls
    • Secrets stay in your vault; agents receive scoped credentials only
    • Policy enforcement at the gateway before a request reaches a model
    • Independent penetration testing of the platform

    Data & privacy

    • No training on customer data, ever - in any mode
    • No prompt or code stored on Kimchi-operated infrastructure in Serverless or Self-Hosted modes
    • You choose the processing region per workload
    • BYOK routing keeps frontier traffic under your own provider terms

    Internal security procedures

    • Documented incident response and escalation plan
    • Change management with peer review before production
    • Business continuity and disaster recovery planning
    • Annual risk assessment and vendor review

    Governance

    • Hard budget caps enforced per user, team, API key and org
    • Approved model and skills registry
    • Real-time spend and usage attribution
    • Policy approval required before any external model call
    Data residency

    You choose where your data is processed.

    Serverless runs on Kimchi-owned GPUs. Self-Hosted runs entirely in your own Kubernetes cluster with zero dependency on our infrastructure. Frontier BYOK routes directly to your provider under your own key. The mode is always explicit.

    See all three modes
    ServerlessKimchi-owned GPUs · FR · IL · US
    Self-HostedYour VPC · your region · air-gappable
    Frontier BYOKDirect to your provider · your key
    Corporate

    Kimchi is part of the Cast AI Group.

    Kimchi is the AI coding platform built by the team behind Cast AI. Group-level security governance, compliance certifications and vendor management apply to Kimchi, and the full evidence library is published in the Cast AI Trust Center.

    trust.cast.ai
    Contact

    Security questions or reports.

    For security reviews, questionnaires, documentation requests or vulnerability reports, get in touch and our team will respond.