Trust & security

How Kynoa protects personal data under the DPDP Act.

Kynoa is built around India's Digital Personal Data Protection Act. Personal data is anonymised before analysis, stored in India and fully auditable.

Anonymisation

What happens to personal data

Every record passes through four stages before it can reach a model.

  1. Raw record

    A resume or profile that contains personal data.

    Contains PII
  2. One-way hash

    Names, emails and IDs are replaced with salted SHA-256 hashes that cannot be reversed.

    a7f3b2…9d4e
  3. Grouping

    Records are grouped so that no result describes fewer than 50 people (k-anonymity, k ≥ 50).

    k ≥ 50
  4. Model features

    Only anonymous, aggregated features are stored for modelling.

    No PII retained

DPDP Act 2023

Consent

Explicit, purpose-specific consent, with opt-out as easy as opt-in.

Data in India

All personal data is stored on AWS Mumbai (ap-south-1), with no cross-border transfer.

Right to erasure

Deletion requests are completed within 48 hours, with an audit record.

Data fiduciary duties

Data protection impact assessments for new uses of personal data.

Grievance redressal

A named Grievance Officer with defined response times.

Infrastructure security

SOC 2 Type II controls

Controls are in place and monitored continuously. The independent audit report has not been issued yet.

Encryption

AES-256 at rest and TLS 1.3 in transit. No personal data is stored in plain text.

Access control

Role-based access with enforced MFA and least-privilege permissions.

Audit logs

Tamper-evident logs of all data access, with alerts on unusual activity.

Penetration testing

Quarterly third-party penetration tests.

Control for the people behind the data

Professionals who use Kynoa decide what they share.

Explicit opt-in

Nothing is collected without informed consent. Each use of data needs the person's active agreement.

Field-level choices

People choose exactly which details to share, with a preview of what will be visible.

Delete any time

One action deletes a profile and all its data from every system within 48 hours.

Where each framework stands today

We would rather tell you exactly where we are than overstate it.

DPDP Act 2023

Designed for

Consent, purpose limitation, erasure and grievance redressal built in.

SOC 2 Type II

Audit-ready controls

Controls are in place; the independent audit report has not been issued yet.

ISO 27001

In progress

ISMS documentation underway.

GDPR

Principles applied

Applied where EU data subjects are involved.

Frequently asked questions

Can we see your SOC 2 report?

Our SOC 2 Type II audit report has not been issued yet. Book a security review and we will walk you through the controls we have in place.

Where is data stored?

All personal data is stored in India on AWS Mumbai (ap-south-1). It is not transferred abroad.

Do enterprise customers ever see individual-level data about non-employees?

No. Market data is aggregated so that no result describes fewer than 50 people.

Security questions? Let's talk.

Our team will walk you through the architecture, controls and compliance roadmap.

See Kynoa on your own data Book a demo (opens in a new tab)