Security & data handling

Built to be safe to connect

Every Kaleidoscope MCP server follows the same contract: read-only tools over our own corpora of public-filing data, nothing of yours ingested, and nothing you ask used to train models.

The contract

How we handle your data

The questions legal, compliance, and security teams ask first — answered plainly.

Your queries are not used for training

Questions you ask and results you receive are not used to train models — ours or anyone else's.

We never see your documents

No customer documents are ingested or stored. Every server reads only from our own corpora, built from public filings and disclosures.

Read-only, side-effect-free tools

Every tool is read-only and annotated as such in the MCP envelope — no writes, no mutations, nothing to approve call-by-call. Well-behaved clients can auto-approve the whole server.

Email sign-in, no long-lived tokens

Authentication is a one-time email sign-in your client opens in the browser. There are no API keys or bearer tokens to store, rotate, or leak.

Access by invitation

Every server is allowlist-gated per email. Your team's access covers exactly the servers your engagement includes — nothing is open by default.

Hosted on AWS (US-East)

All infrastructure runs on Amazon Web Services in the US-East region, with transport encrypted via TLS.

Questions

Need something in writing?

If your security review needs specifics beyond this page — data-flow diagrams, subprocessor details, or contractual terms — email support@kscope.io and we'll work through it with your team.

Safe to evaluate, easy to start

Request a demo — we'll walk through the data and the trust contract on your own questions.

Request a Demo