Security and data

Where your data is, and where it isn't.

kiweely is local-first: the work happens on your computer, against your own tenant, with your own accounts. This page says exactly what that means — and what it doesn't.

On your computer

Your conversations and the apps it builds
Stay on your computer. The app's own conversation database is encrypted at rest (SQLCipher, with keys held in your operating system's secure store). The AI engine inside kiweely also keeps its own session logs on your computer, in a folder only your user account can read — those logs are protected by your login, not separately encrypted. We say this because it is true, and because “everything is encrypted” would not be.
Your Workday sign-in
Lives only in macOS Keychain. kiweely never sends it to the Kiweely account or product authorization services. It acts on your tenant as you, through your own session, with the reach you already have and no more.
Your ChatGPT sign-in
Done once inside the app, under Settings → AI Connections, and stored by the AI engine on your computer. kiweely has no account of its own in between: there is no backend key we hold, and we cannot read what you and the agent say to each other.

What leaves your computer, and to whom

OpenAI
Everything in the conversation — your request, the files the agent reads and writes, the errors Workday returns — goes to OpenAI under your own ChatGPT account, on every turn. That is how the agent works. OpenAI's terms for your plan apply; kiweely is not a party to that relationship and never sees the traffic.
Your Workday tenant
The app source, validation requests, publishes and deploys you approve, sent with your own credentials to the tenant you connected. Nothing touches a tenant you did not connect.
Kiweely product authorization
When you authorize a Mac and refresh its lease: an opaque account/entitlement reference, random installation ID, installation public-key digest, platform/app version, grant proof, account revocation version, and lease dates/counter. It receives no email, Stripe ID, billing address, invoice, card data, conversation, Workday credential, or hardware serial number. A signed lease is refreshed daily and expires after at most 72 hours offline.
Nobody else
kiweely sends no usage analytics, no telemetry and no crash reports. If the app fails, the only thing that leaves your computer is what you choose to paste into an e-mail to us — and the “Copy details for support” button scrubs credentials out first.

Our side

Product authorization runtime
Runs separately on Google Cloud in the United States (us-central1). It stores opaque entitlements, installations, one-use activation grants, leases, idempotency and audit records—without commercial customer PII or Stripe access.
Payments
Stripe hosts Checkout and the Customer Portal and handles payment credentials, invoices, fraud, disputes and tax. Card numbers go to Stripe, not to kiweely. The commercial database keeps only the customer/subscription/invoice references and verified state needed for billing, support and entitlement projection.
Every provider, named
Auth0 handles identity, Google Cloud hosts the website/customer API/databases/product runtime/releases, Stripe handles billing and tax, and Resend handles Kiweely transactional email. Purposes and data categories stay current on the Subprocessors page.

Where we actually are

kiweely has not completed SOC 2, a third-party penetration test, or any other attestation. We will not imply otherwise on a sales call. If your security review needs one of those before a pilot, tell us — we would rather know than sell around it.

Found a security issue?

Write to support@kiweely.com with what you found and how to reproduce it. We acknowledge reports within two business days, fix confirmed issues before we announce them, and credit you if you want us to. The same address is published at /.well-known/security.txt.