What follows is not a description of how the masking is done. It is a description of where your data goes, what is kept, who can read it, and what happens when you take a key away.هذه ليست شرحاً للتقنية، بل بياناً واضحاً لمآل بياناتكم.
Raw text never crosses the Kingdom's border. The masked text does, and only the masked text. The frontier model sees placeholders; your client restores the originals locally.
If KINDI were compelled to disclose what it holds on a given request, the disclosable record is the list below. The request text, the response text, and the mapping are not on it.
Your API key is the root of trust. KINDI can produce an envelope; it cannot read one. Only a holder of the API key can.
Compute, primary storage, backups, and operational logs all run inside the Kingdom of Saudi Arabia. Data does not transit a foreign region in the course of normal operation, save for the masked text your client sends to the frontier model.
Statements of alignment posture. Independent attestation is in preparation; this section will cite the attestation when received. Until then, these are positions, not certifications.
A short catalogue of access, by role. The principle is simple: the fewer hands that touch your text, the better; in practice, none of KINDI's do.
Third parties that participate in operating the service, the data they receive, and where they operate. Changes to this list are published before they take effect.
| Role | Vendor | What they receive | Region |
|---|---|---|---|
| Hosting | In-Kingdom hosting provider | the encrypted envelope and masked text in transit; nothing in cleartext at rest | Kingdom of Saudi Arabia |
| Transactional email | Email delivery provider | your registered email address and the body of operational notices (receipts, password resets); never the body of a masking request | Multi-region; KSA preferred where available |
| Payments | Tap Payments, forthcoming | top-up amount, billing identity, card token; only at the moment of a top-up | Kingdom of Saudi Arabia |
KINDI's posture on a confirmed material incident affecting customer data or service availability.
For procurement reviews, due-diligence questionnaires, or anything this page leaves unanswered.