Security you can verify.
Kimchi is part of the Cast AI Group. We run on the same security program, certifications and controls as Cast AI, applied to an AI coding platform where your code and prompts stay inside a boundary you define.
Certifications and attestations.
Compliance is maintained at the Cast AI Group level and covers the Kimchi platform. Reports and evidence are available under NDA through the Cast AI Trust Center.
Independently audited controls for security and availability.
Certified information security management system.
Attestation of Compliance on file for card data handling.
HIPAA-ready architecture. BAA available on request.
How the program is enforced.
Controls are monitored continuously across infrastructure, people, product and process - not reviewed once a year.
Infrastructure security
- ›Data encrypted in transit (TLS 1.2+) and at rest
- ›Network segmentation and least-privilege service roles
- ›Continuous infrastructure monitoring and alerting
- ›Self-Hosted mode runs entirely inside your own VPC
Organizational security
- ›Background checks for personnel where permitted by law
- ›Mandatory security awareness training
- ›Role-based access with SSO/SAML/OIDC and MFA
- ›Documented onboarding and offboarding procedures
Product security
- ›Per-request audit trail for prompts, completions and tool calls
- ›Secrets stay in your vault; agents receive scoped credentials only
- ›Policy enforcement at the gateway before a request reaches a model
- ›Independent penetration testing of the platform
Data & privacy
- ›No training on customer data, ever - in any mode
- ›No prompt or code stored on Kimchi-operated infrastructure in Serverless or Self-Hosted modes
- ›You choose the processing region per workload
- ›BYOK routing keeps frontier traffic under your own provider terms
Internal security procedures
- ›Documented incident response and escalation plan
- ›Change management with peer review before production
- ›Business continuity and disaster recovery planning
- ›Annual risk assessment and vendor review
Governance
- ›Hard budget caps enforced per user, team, API key and org
- ›Approved model and skills registry
- ›Real-time spend and usage attribution
- ›Policy approval required before any external model call
You choose where your data is processed.
Serverless runs on Kimchi-owned GPUs. Self-Hosted runs entirely in your own Kubernetes cluster with zero dependency on our infrastructure. Frontier BYOK routes directly to your provider under your own key. The mode is always explicit.
See all three modesKimchi is part of the Cast AI Group.
Kimchi is the AI coding platform built by the team behind Cast AI. Group-level security governance, compliance certifications and vendor management apply to Kimchi, and the full evidence library is published in the Cast AI Trust Center.
trust.cast.aiSecurity questions or reports.
For security reviews, questionnaires, documentation requests or vulnerability reports, get in touch and our team will respond.