Trust
Your workloads stay yours.
Optimizing GPU code means handling traces that describe your models and infrastructure. We treat that data as sensitive by default.
Security practices
Data
Encryption in transit and at rest
Traffic uses TLS 1.2+. Stored traces and generated kernels are encrypted at rest with provider-managed keys.
Isolation
Per-customer workspaces
Each customer's profiling data and optimization jobs run in logically isolated workspaces with separate access scopes.
Access
Least-privilege access
Staff access to production is limited, requires SSO with multi-factor authentication, and is logged.
Retention
You control your data
Workload traces can be deleted on request. Your data is never used to optimize workloads for other customers.
Deployment
On-premise option
For sensitive workloads, profiling can run inside your own environment so traces never leave your infrastructure.
Vendors
Reviewed subprocessors
Infrastructure and service vendors are reviewed before use and bound by data protection terms.
Compliance roadmap
| Framework | Status | |
|---|---|---|
| GDPR | Aligned | DPA available on request |
| SOC 2 Type I | Planned | Not yet certified |
| ISO 27001 | Planned | Not yet certified |
Responsible disclosure
If you believe you've found a vulnerability, email security@kernova.ai with steps to reproduce. We acknowledge reports within two business days and won't pursue legal action against good-faith research that avoids privacy violations and service disruption.
Practices describe the intended security posture. Verify each statement matches your actual setup before publishing.