KINDI · A bureau for handling sensitive language.

In-Kingdom PII masking for frontier LLMsRiyadh · Kingdom of Saudi ArabiaPreview
KINDI.me
09 Aug 2026 · 1448-02-26 HRiyadh · --:-- AST
PL. 20 · TRUSTData conduct, plainly stated

Your text stays in the Kingdom. The masked text crosses the border. Nothing of either is retained beyond the request, except the files you explicitly upload for redaction.

What follows is not a description of how the masking is done. It is a description of where your data goes, what is kept, who can read it, and what happens when you take a key away.

PL. 20 · § 01
§ I.

The boundary

Raw text never crosses the Kingdom’s border. The masked text does, and only the masked text. The frontier model sees placeholders; the originals are restored inside the Kingdom, in your own client or, on the optional proxy path, by KINDI before the response is returned to you.

Inside the Kingdom
  • Raw input text, for the duration of the request
  • Masking and encryption, in-region
  • The encrypted envelope, in transit to your client
  • Operational metadata about the call
Outside the Kingdom
  • Masked text, sent to your chosen frontier model
  • The frontier model's masked reply, returned to your client
  • Nothing else: no raw text, no mapping, no envelope
PL. 20 · § 02
§ II.

What is retained

If KINDI were compelled to disclose what it holds on a given request, the disclosable record is the list below. The request text, the response text, and the mapping are not on it.

Retained, per request
timestamp · words metered · status code · API key identifier (not the secret) · originating account · the IP address the request came from
Retained, per account
identity for billing and support · ledger of top-ups and debits · receipts and tax invoices
Not retained, ever
for the text masking and redaction endpoints: request text · response text · placeholder-to-original mapping · the encrypted envelope, beyond the round-trip
Held briefly, encrypted
documents uploaded for file redaction, and their redacted outputs, encrypted at rest in-Kingdom and deleted at the file's expiry, 24 hours by default
Retained until you delete them
glossary terms and reference logos you save to your account, held to serve your requests and removed when you delete them or close the account
Retention period
operational metadata, retained no longer than 18 months · billing records, as required by KSA tax law · audit logs, retained no longer than 24 months
PL. 20 · § 03
§ III.

Keys and revocation

Your API key is the root of trust. KINDI can produce an envelope; it cannot read one. Only a holder of the API key can.

Issuance
every response that contains masked content carries an encrypted envelope; the envelope is sealed against a key derived from your API key
Custody
KINDI does not store the API key or any key derived from it; the secret is shown once, at the moment of creation, and is held only by you
Revocation
revoking an API key invalidates every outstanding envelope by design; previously returned envelopes become unreadable
Override
there is none; an operator cannot decrypt on your behalf
PL. 20 · § 04
§ IV.

Residency

Compute, storage, backups, and operational logs all run inside the Kingdom of Saudi Arabia. Data does not transit a foreign region in the course of normal operation, save for the masked text sent to the frontier model, whether your own client sends it or KINDI’s optional proxy forwards it on your behalf.

PL. 20 · § 05
§ V.

Regulatory alignment

In draft

Statements of alignment posture. Independent attestation is in preparation; this section will cite the attestation when received. Until then, these are positions, not certifications.

PDPLPersonal Data Protection Law (KSA)
Designed against; not certified.
NCA ECCEssential Cybersecurity Controls (ECC-2:2024)
Designed to align.
NCA CCCCloud Cybersecurity Controls
Designed to align.
NCA DCCData Cybersecurity Controls (DCC-1:2022)
Designed to align.
PL. 20 · § 06
§ VI.

Who can read what

A short catalogue of access, by role. The principle is simple. The fewer hands that touch your text, the better. In practice, none of KINDI’s do.

You
full read and write on your account, your keys, your balance, and your usage history; sole holder of the secret used to decrypt envelopes
KINDI operators
aggregate operational metrics (latency, error rate, throughput) · your account identity for billing and support · no access to request text or response text, by policy and by construction
Independent auditors, where a customer engagement requires one
admin-action audit trail · access reviews · incident records · never the body of customer requests
Logging policy
production logs exclude request text, response text, email addresses, and bearer tokens at INFO level or above; only identifiers travel up the log pipeline
PL. 20 · § 07
§ VII.

Sub-processors

Third parties that participate in operating the service, the data they receive, and where they operate. The Sub-processor List is the authoritative record, and states what each entry receives in full. Changes are published at least 14 days before they take effect, and a customer that objects on reasonable data-protection grounds may terminate within that notice period.

RoleVendorWhat they receiveRegion
HostingIn-Kingdom hosting providerthe encrypted envelope and masked text in transit; nothing in cleartext at restKingdom of Saudi Arabia
DNS and TLS issuanceCloudflareDNS records for kindi.me and its subdomains, for certificate issuance; no request text, no response text, no personal dataGlobal edge; DNS records only
Transactional emailResendyour registered email address and the body of operational notices (receipts, password resets); never the body of a masking requestUnited States and European Union
Language-model provider (proxy, optional)OpenAImasked request text only, and only when you route a request through the proxy to one of its modelsUnited States
Language-model provider (proxy, optional)Anthropicmasked request text only, and only when you route a request through the proxy to one of its modelsUnited States
PaymentsTap Payments, forthcomingtop-up amount, billing identity, card token; only at the moment of a top-up. Not yet engagedKingdom of Saudi Arabia
PL. 20 · § 08
§ VIII.

Incidents

KINDI's posture on a confirmed material incident affecting customer data or service availability.

Customer notification
within 72 hours of confirmation, to the registered account email, including known scope and the steps in motion
Regulator notification
within the timelines required by the PDPL and any applicable NCA guidance. For personal-data incidents, notification to SDAIA within 72 hours of confirmation; coordinated with counsel
Running updates
sent to the registered account email until resolution; a live component check is published at status.kindi.me
Responsible disclosure
security researchers may report findings through the contact form under the security topic; we acknowledge within one business day
PL. 20 · § 09
§ IX.

Trust correspondence

For procurement reviews, due-diligence questionnaires, or anything this page leaves unanswered. All correspondence goes through the contact form at kindi.me/contact; no email addresses are published.

Data Protection
contact form · mark the note for data protection
Security
contact form · security topic
General
contact form · reply within one business day, Sunday through Thursday