# AI you can trust. With Enterprise-grade security.

> AI you can trust: certified in ISO 27001, 27701 and 42001 and ENS, compliant with the GDPR and the EU AI Act. Adjustable autonomy, full traceability, isolated information.

*Source: <https://kelp.work/en/security> · Kelp Labs, Madrid.*

AI tailored to your organisation, built for IT, Security, Compliance and Legal to sign off.

[Tailored demo →](mailto:hola@kelp.work?subject=Kelp%20demo) [See certifications](https://kelp.work/en/security#certificaciones)

## Certifications and compliance.

We keep an [AI enquiries channel](https://kelp-labs.com/legal/ai-canal-consultas) open to clients, employees and third parties. If your due diligence needs more, ask and we will show you.

Spain's National Security Framework. Public-sector rigour.

The international standard for information security. Your data, kept safe.

The international standard for privacy. Personal data, handled properly.

Responsible management of AI systems. Very few companies hold it.

Coming soon

The American equivalent of our ISOs: the same controls, already audited.

The European data protection regulation. Your clients, protected.

Spain's data protection law, Organic Law 3/2018 (LOPDGDD), which implements the GDPR.

The European AI regulation. Compliance is not optional: we are ahead of it.

Independent Data Protection Officer, registered with the Spanish Data Protection Agency (AEPD).

Data processing agreement (Art. 28 GDPR), signed before a single piece of data is processed.

[PDFSecurity policy](https://cdn.kelp-labs.com/ENS_Poli%CC%81tica%20de%20Seguridad_signed.pdf) [PDFAI policy](https://cdn.kelp-labs.com/Politica_IA_KelpLabs_v1.pdf) [AI enquiries channel](https://kelp-labs.com/legal/ai-canal-consultas) Updated: August 2026

## Enterprise Ready. Kelp fits into your organisation without friction.

Security, compliance and governance are the foundation, certificate by certificate. Enterprise Ready also means a phased rollout, a tailored deployment and your supplier approval process, passed.

First, a turnkey pilot on your real cases, with scope, price and measurable objectives agreed before starting. Then a phased rollout to the rest of the operation. Our team works alongside yours, on the business and the technology side, until it is running: live in weeks, without taking months of your team's time.

Kelp can be deployed on your organisation's cloud infrastructure and work with the AI models you have already approved, through your own API keys: what is known as bring your own cloud and bring your own key. On Azure, Kelp is deployed in your Azure and uses the models through Azure OpenAI; on Google Cloud, through Vertex AI. Each deployment is designed with your IT team.

Security questionnaires, due diligence, supplier validation: we answer them with documentation. ENS certificates and ISO 27001, 27701 and 42001, a DPA signed before a single piece of data is processed, a DPO registered with the AEPD and any further evidence your process requires. If procurement, security or legal need more than what is published, we show it.

We agree the SLAs with you and they go into the contract: availability, support and response times to fit your operation. After the rollout, the Kelp team keeps working alongside yours, with a direct channel.

## What Kelp does. What it doesn't.

It comes as standard: it is in how Kelp is built.

**Always** What it does

- **Encrypts everything.** TLS 1.2+ in transit, AES-256 at rest.

- **Isolates each account.** Permissions by role and by client, no crossover.

- **Logs every action.** Every decision, change and deliverable, with its reason and its source.

- **Waits for your sign-off.** Nothing important goes out without it.

- **Keeps keys separate.** Credentials in an encrypted vault, away from the models.

- **Sign in with your SSO.** Google Workspace, Microsoft Entra ID and SAML 2.0.

**Never** What it doesn't do

- **Train models on your data.** Neither ours nor the providers'.

- **Make up an answer.** If it doesn't know, it says so or escalates to a person.

- **Mix information between your clients.** Each account lives in its own compartment.

- **Work where you haven't invited it.** It sees what that group sees, nothing more.

- **Tell anyone what they shouldn't see.** Answers respect the permissions of the person asking.

- **Sell or share your data.** With no one. Not aggregated, not anonymised.

## How far does Kelp act without your permission?

Kelp proposes and you decide. We configure autonomy with you by type of work, and the final word is always yours.

**Autonomy · House rules** Saved

**Internal work** Notes, minutes, summaries

**Meeting preparation** Briefs, dossiers, follow-up

**Proposals and deliverables** What is being prepared

**What the client sees** Sends, deliveries, replies

## Traceable to its source.

Every recommendation, alert or deliverable comes from your meetings, emails and systems, and can be traced level by level back to its origin.

## Where does your firm's data live?

Your firm's information is never mixed with anyone else's. Nor between your own clients: each account lives in its own compartment.

Each account, in its own compartment

Permissions by role and by account

Every access is logged

**Nothing is lost** Encrypted backups and tested recovery. A bad day deletes nothing.

**Infrastructure in the EU** Your data is stored and processed in the European Union, under European law.

**If you leave, it leaves with you** Full export of everything that is yours and verifiable deletion at the end.

## Ask anything.

Security and compliance are answered with documents. Ask for them in the demo.

[Tailored demo →](mailto:hola@kelp.work?subject=Demo%20de%20Kelp)

## Questions about security and compliance.

The ones that come up in a client due diligence or a security committee.

[Talk to us →](mailto:hola@kelp.work?subject=Kelp%20demo)

### What certifications does Kelp hold?

Kelp is certified under Spain's National Security Framework (ENS) and the ISO 27001, ISO 27701 and ISO 42001 standards, and complies with the GDPR, the LOPDGDD and the EU AI Act. SOC 2 Type II is on the way. There is an external DPO appointed and registered with the AEPD, a DPA signed with each client, and an [AI enquiries channel](https://kelp-labs.com/legal/ai-canal-consultas) open to clients, employees and third parties.

### Can I use Kelp with my clients' data?

Yes, that is exactly what it is built for. Your firm's information is kept isolated and processed in the European Union, under European law. Each client account lives in its own compartment, with no crossover, permissions by role and by client and every access logged. Everything is encrypted: TLS 1.2 or higher in transit and AES-256 at rest.

### Does Kelp train models on our information?

Never. Neither Kelp's models nor the providers' are trained on your data. Nor is it sold or shared with anyone, not even aggregated or anonymised. And Kelp does not work where you haven't invited it: it sees what that group sees and nothing more.

### My team already uses ChatGPT on their own. How do I bring order to AI use in the firm?

By putting it inside a perimeter that can be audited. With Kelp every action is logged with its reason and its source, permissions are by role and by client, you sign in with your Google Workspace, Microsoft Entra ID or SAML 2.0 SSO, and credentials live in an encrypted vault, away from the models. Loose personal accounts with client information inside stop existing.

### What happens to our information if we stop using Kelp?

It leaves with you: full export of everything that is yours and verifiable deletion at the end. In the meantime backups are encrypted and recovery is tested, so a bad day deletes nothing. And if your due diligence needs more documentation than what is published, ask and we will show it.

### Which AI models does Kelp use and where is the data processed?

Kelp works with models from the leading providers under contracts that prohibit training on your data, and all information is processed and stored in the European Union. If your organisation requires it, Kelp uses the models you have already approved through your own API keys, such as Azure OpenAI or Vertex AI.

### Who in my firm can see what inside Kelp?

Whatever their permissions let them see. Permissions are by role and by client, Kelp's answers respect the permissions of the person asking, and in chat Kelp is only in the groups you have invited it to. Every access is logged.
