Security Always on. Always secure.

Your data is in safe hands.

From encryption to access management, Kritical enforces rigorous standards to ensure your data stays secure, private, and compliant.

Certifications in progress

Kritical is committed to maintaining compliance with the most rigorous international safety and security standards.

ISO 27001

ISO 27001, certification in progress: the internationally recognized standard for information security management.

ISO 42001

ISO 42001, certification in progress: the international standard for how AI systems are governed, built, and operated.

SOC2 Type 2

SOC 2 Type 2, planned: an independent audit of security, availability, and confidentiality controls.

Trusted data storage

  • Tiered Storage

    Kritical offers flexible storage options designed to match different data sensitivity levels and compliance needs.

  • No foundation model training

    Your confidential data remains secure and private to you. Kritical will not use your data to train or fine tune any AI models.

Legal-grade security

  • Zero trust design principles

    We follow Zero Trust architecture, meaning no user or system is inherently trusted: access is always verified, limited, and logged.

  • Your approval required

    Access to customer data is strictly controlled and only granted to engineers with written customer approval for support-related issues.

  • Regular security audits

    Kritical undergoes semi-annual penetration tests covering the full platform scope and follows an “assume breach” methodology to proactively identify and mitigate risks.

  • Trusted infrastructure

    Kritical's access control is built on the Zanzibar authorization system: the same proven infrastructure that powers Google Drive, YouTube, and other large-scale applications.

Deployment Where your data lives

Deploy Kritical where your data needs to live.

From a fully managed cloud to a deployment inside your own perimeter. Kritical runs where your governance requires: encrypted end to end, access controlled, and never used to train AI models.

Available now

Kritical Cloud

Fully managed on our secure cloud. The fastest way to get your whole project record classified, searchable, and traceable, with security handled for you. Data is encrypted in transit and at rest, isolated per customer, and hosted in the region you choose. Patching, monitoring, and backups are ours to run.

On request

Your Cloud / VPC

Deployed into your own AWS, Azure, or GCP tenancy, so your data never leaves your perimeter. Private networking keeps traffic off the public internet, you hold your own encryption keys, and access is scoped to your identity provider. The managed experience with the data residency your governance requires.

On request

On-prem

Runs entirely inside your own data center, behind your firewall. Air-gap capable for the most sensitive environments, with full control over data, models, and access. Nothing calls home: you decide what runs, where, and who can reach it, with a complete audit trail.

Your data. Your decisions.

You maintain control over your data at all times.

Data retention

Set and manage data retention periods to align with your internal policies and regulatory requirements.

Data governance

Kritical's Data Governance tools give you real-time insight into who's accessing your data and when.

Encryption management

Manage your own encryption keys with our BYOK option to keep sensitive data protected at all times.

User authentication

SSO integration gives you complete control over user authentication and access management.

FAQ

How does Kritical encrypt data?

At Kritical, protecting your data is our top priority. All data is encrypted in transit using TLS 1.2 or higher, and at rest with AES-256 encryption. For customers who require additional control, we also offer the option to encrypt data with their own encryption keys. If this is of interest, please let us know.

How does Kritical manage customer data?

Our customers entrust us with some of their most sensitive and confidential information, a responsibility we take extremely seriously. With Kritical, you can be confident that your data is accessible only to your authorized users. Kritical will never access your data without your explicit written consent.

How does Kritical handle AI transparency and explainability?

Transparency is core to how we build AI. Every AI output generated in Kritical can be traced back to the source data and prompt that produced it. This means you can always review the AI's reasoning, examine the sources it relied on, and verify its conclusions.

What happens to our data when we stop using Kritical?

Once your contract ends, all of your data, along with any dedicated storage resources associated with your account, is permanently deleted. Before this happens, you'll have the opportunity to request a full export of your data to ensure you retain everything you need.