Authentication & Compliance
1\ introduction and purpose this document provides kindly ai's customers with a comprehensive overview of the security and compliance standards governing the chat authentication feature the purpose is to offer transparency into the robust security controls, data handling practices, and regulatory alignment of our authentication process this document is intended to support our customers' internal compliance and security assessments 2 scope this overview applies to the user authentication feature available for the kindly ai chat widget it details the end to end process, from the generation of an authentication token by the customer's system to the establishment of a secure, verified chat session on the kindly ai platform 3 authentication method kindly ai utilizes a secure, industry standard authentication method using json web tokens (jwt) to verify user identities and enable a seamless, secure chat experience authentication flow the customer is responsible for creating a secure authentication endpoint on their own systems when a logged in user initiates a chat, the customer's endpoint generates a signed jwt this token is then passed to the kindly ai chat widget, which forwards it to our platform for verification upon successful validation, the user is authenticated within the chat session jwt security standards algorithm we mandate the use of the rs256 (rsa signature with sha 256) algorithm for signing the jwt this asymmetric cryptographic standard ensures that the token's integrity and authenticity can be verified without exposing the private signing key key management the customer generates a private/public key pair the private key remains securely within the customer's environment and is used for signing the jwt the customer registers their public key within their kindly ai bot settings, allowing our platform to securely validate the jwt signature 4\ data security and privacy at kindly ai, the security of all data processed on our platform is paramount the chat authentication feature is underpinned by our comprehensive security program data encryption in transit all communication between the end user's browser, the customer's servers, and the kindly ai platform is encrypted using strong transport layer security ( tls 1 2+ ) data encryption at rest any data stored within the kindly ai platform is protected by aes 256 encryption, a leading industry standard for securing data at rest data residency all authentication data is processed and stored in secure data centers located within the european union (eu) data minimization & anonymization our platform is designed to support the principle of data minimization the jwt payload can be configured by the customer to include only the essential information required for the chat interaction furthermore, kindly ai provides features for the automatic masking and anonymization of sensitive data, which can be configured by the customer to prevent the storage of non essential personally identifiable information (pii) 5\ compliance and regulatory adherence the kindly ai platform is designed and operated in adherence to stringent international security and privacy standards iso/iec 27001 2022 certification kindly ai maintains an iso/iec 27001 2022 certification for our information security management system (isms) this certification is independently audited and demonstrates our commitment to the highest standards of information security general data protection regulation (gdpr) we have structured our services and agreements to facilitate our customers' compliance with the gdpr data controller vs data processor under the gdpr, the customer acts as the ‘data controller’ , as you determine the purposes and means of processing personal data kindly ai acts as the ‘data processor’ , processing data on behalf of and upon the instruction of the customer data processing agreement (dpa) we provide a comprehensive dpa that contractually governs our data processing activities in line with gdpr requirements 6\ roles and responsibilities a secure authentication process relies on a shared responsibility model kindly ai's responsibilities providing a secure and compliant chat platform securely storing the customer's public key and using it to validate jwt signatures maintaining the security and integrity of our platform infrastructure in line with our iso 27001 certification processing data strictly in accordance with the dpa customer's responsibilities developing and maintaining a secure authentication endpoint securely managing the private key used for signing the jwt access to this key must be strictly controlled ensuring the jwt payload is correctly configured and does not contain superfluous personal data fulfilling their obligations as the data controller, including obtaining necessary user consents and managing user data rights for further technical details, please refer to our official documentation for any additional security or compliance inquiries, please contact your customer success manager