Our security posture, transparent by default.
We sell a Trust Center to our customers. We use one ourselves. Request any artifact below, no sales call required.
Available for your security review.
SOC 2 Type II
In progressAnnual audit covering security, availability, and confidentiality trust service criteria. Report available upon completion.
Request status updateSecurity whitepaper
AvailableArchitecture overview, encryption standards, identity controls, tenant isolation model, and vulnerability management practices.
Request accessData Processing Agreement (DPA)
AvailableStandard DPA covering data processing terms, sub-processors, and data residency commitments.
Request DPAPenetration test summary
Available under NDAAnnual third-party penetration testing with documented remediation. Summary available to qualified prospects.
Request under NDAVulnerability disclosure
ActiveReport potential security issues to security@kyudo.ai. We acknowledge within 24 hours and triage within 72 hours.
Report a vulnerabilityHow we protect your environment.
About Kyudo, Inc.
Need something not listed here? Reach out to our security team directly.
Questions, answered
Kyūdō deploys inside your own Microsoft Azure tenant as containerized services running on Azure, provisioned through the Azure Managed Application model. The platform operates where your data already lives, so there is no cross-tenant data plane and no vendor-hosted copy of your compliance evidence. Deployment is handled with your Azure administrator during onboarding, and the application layer is maintained by Kyūdō while you retain control of the Azure subscription and the data within it.
Your compliance data lives entirely inside your own Microsoft Azure tenant and never leaves it. There is no cross-tenant data plane and no vendor-side copy of your evidence. Under the Azure Managed Application model, the provider holds standing least-privilege access scoped only to the managed resource group that runs the application, not to your compliance data or your wider tenant. In practice this means no vendor access to your compliance data, which removes the data-export exposure multi-tenant SaaS compliance tools carry.
Kyūdō's AI reasons over a typed Compliance Graph, a structured model of your controls, evidence, frameworks, and their relationships, rather than generating text over a flat database. Every AI output carries a confidence score, and results below a defined threshold are routed to a human for review before they are accepted. Each answer cites the specific source nodes it draws from, so you can trace a conclusion back to the underlying evidence. The agent runtime is Microsoft Foundry Agent Service, running inside your tenant.
Yes, because Kyūdō is built for auditor scrutiny rather than unexplained automation. Every AI-assisted conclusion cites the source nodes in the Compliance Graph it was derived from, carries a confidence score, and is sealed with a cryptographic chain of custody. Outputs below a defined confidence threshold require human disposition before they count as evidence, keeping a person in the loop for consequential decisions. An auditor can follow any artifact from the AI's statement back to the Microsoft Security signal that produced it.
Kyūdō builds evidence from core Microsoft Security signals: Microsoft Defender for threat protection, Microsoft Sentinel for security information and event management, Microsoft Purview for data governance and information protection, Microsoft Entra ID for identity and access, and Azure Policy for configuration and guardrails. These signals are read continuously inside your tenant and converted into governed control evidence. Treating Microsoft as the primary evidence source, rather than one connector among hundreds, is what lets Kyūdō produce deep, continuous proof from infrastructure you already run.
Yes. Because Kyūdō runs inside your Azure tenant, encryption keys remain under your control, and the platform supports customer-managed keys through Azure Key Vault. Data is encrypted in transit and at rest using your tenant's key management, so the provider never holds the keys to your compliance data. This is a direct consequence of the deployment model: when the application and its data live in your tenant, key custody stays with you rather than with a SaaS vendor.
Kyūdō is secured by the same Microsoft-native controls it helps you govern. It runs as least-privilege containerized services on Azure Kubernetes Service inside your tenant, isolated to a managed resource group, with identity through Microsoft Entra ID and monitoring through your own Defender and Sentinel. KMicro Tech builds and maintains Kyūdō as a Microsoft Solutions Partner for Security and MISA member. Because there is no central multi-tenant store of customer evidence, there is no shared pool of compliance data to breach.
Kyūdō is built by a Microsoft Solutions Partner for Security and a member of the Microsoft Intelligent Security Association (MISA), the partner ecosystem Microsoft maintains for vetted security solutions. The platform is built on Microsoft-native services, including Microsoft Foundry Agent Service as its agent runtime and Microsoft Security signals as its evidence source, and is being registered for Microsoft co-sell. These credentials reflect that Kyūdō is designed around the Microsoft security stack rather than bolted onto it.
Kyūdō applies its own platform to its own posture, governing its controls, evidence, and AI systems the same way it does for customers. It runs on least-privilege, Microsoft-native infrastructure and uses continuous evidence collection internally, so its compliance state stays current rather than assembled for review. Because the architecture keeps each customer's evidence inside that customer's tenant, there is no central store of customer compliance data for Kyūdō to secure on their behalf, which reduces the shared risk surface.
Looking for more? See all frequently asked questions.
