What follows is not a description of how the masking is done. It is a description of where your data goes, what is kept, who can read it, and what happens when you take a key away.
Raw text never crosses the Kingdom’s border. The masked text does, and only the masked text. The frontier model sees placeholders; the originals are restored inside the Kingdom, in your own client or, on the optional proxy path, by KINDI before the response is returned to you.
If KINDI were compelled to disclose what it holds on a given request, the disclosable record is the list below. The request text, the response text, and the mapping are not on it.
Your API key is the root of trust. KINDI can produce an envelope; it cannot read one. Only a holder of the API key can.
Compute, storage, backups, and operational logs all run inside the Kingdom of Saudi Arabia. Data does not transit a foreign region in the course of normal operation, save for the masked text sent to the frontier model, whether your own client sends it or KINDI’s optional proxy forwards it on your behalf.
Statements of alignment posture. Independent attestation is in preparation; this section will cite the attestation when received. Until then, these are positions, not certifications.
A short catalogue of access, by role. The principle is simple. The fewer hands that touch your text, the better. In practice, none of KINDI’s do.
Third parties that participate in operating the service, the data they receive, and where they operate. The Sub-processor List is the authoritative record, and states what each entry receives in full. Changes are published at least 14 days before they take effect, and a customer that objects on reasonable data-protection grounds may terminate within that notice period.
| Role | Vendor | What they receive | Region |
|---|---|---|---|
| Hosting | In-Kingdom hosting provider | the encrypted envelope and masked text in transit; nothing in cleartext at rest | Kingdom of Saudi Arabia |
| DNS and TLS issuance | Cloudflare | DNS records for kindi.me and its subdomains, for certificate issuance; no request text, no response text, no personal data | Global edge; DNS records only |
| Transactional email | Resend | your registered email address and the body of operational notices (receipts, password resets); never the body of a masking request | United States and European Union |
| Language-model provider (proxy, optional) | OpenAI | masked request text only, and only when you route a request through the proxy to one of its models | United States |
| Language-model provider (proxy, optional) | Anthropic | masked request text only, and only when you route a request through the proxy to one of its models | United States |
| Payments | Tap Payments, forthcoming | top-up amount, billing identity, card token; only at the moment of a top-up. Not yet engaged | Kingdom of Saudi Arabia |
KINDI's posture on a confirmed material incident affecting customer data or service availability.
For procurement reviews, due-diligence questionnaires, or anything this page leaves unanswered. All correspondence goes through the contact form at kindi.me/contact; no email addresses are published.