Every Kaleidoscope MCP server follows the same contract: read-only tools over our own corpora of public-filing data, nothing of yours ingested, and nothing you ask used to train models.
The questions legal, compliance, and security teams ask first — answered plainly.
Questions you ask and results you receive are not used to train models — ours or anyone else's.
No customer documents are ingested or stored. Every server reads only from our own corpora, built from public filings and disclosures.
Every tool is read-only and annotated as such in the MCP envelope — no writes, no mutations, nothing to approve call-by-call. Well-behaved clients can auto-approve the whole server.
Authentication is a one-time email sign-in your client opens in the browser. There are no API keys or bearer tokens to store, rotate, or leak.
Every server is allowlist-gated per email. Your team's access covers exactly the servers your engagement includes — nothing is open by default.
All infrastructure runs on Amazon Web Services in the US-East region, with transport encrypted via TLS.
If your security review needs specifics beyond this page — data-flow diagrams, subprocessor details, or contractual terms — email support@kscope.io and we'll work through it with your team.
Request a demo — we'll walk through the data and the trust contract on your own questions.
Request a Demo