Data handling
What happens to the traces you send us.
Short version: we hold your traces only for the engagement you sent them for, we delete them when it ends or sooner if you ask, and the criteria and labels the work produces are yours and stay with you. The rest of this page is the detail your security reviewer will want.
What we ask for
Traces your AI agent has already produced, and whatever you already capture alongside them. That is the whole of it. We do not ask for access to your production systems, we do not ask for a login to them, and we do not need a copy of your production database to evaluate an agent that runs on it.
Send us the least that answers the question. If a trace can be redacted and still show what the agent did and what evidence it had, redact it. An evaluation cares whether the answer was grounded, complete and correctly cited. It very rarely cares who the customer was.
How long we keep them
Traces are held for the engagement they were sent for, and deleted when it ends. If you ask us to delete them sooner, we delete them sooner and tell you it is done. There is no other reason we would keep them: they are the input to a piece of work, not an asset.
What survives the deletion is the part you actually wanted. The failure taxonomy, the criteria, the rubric, the gold labels your experts produced and the runs behind every number are yours. They are derived from your traces rather than being them, and they stay with you whatever happens to the traces themselves.
How your data is separated from anyone else's
One system, with each client's data separated from every other client's inside it. To be plain about what that is not: it is not separate infrastructure per client. If your review requires physically separate infrastructure, say so on the first call and we will tell you honestly whether we can meet it for your engagement rather than discovering it at signature.
The arrangement that removes the question entirely is for the evaluation to run inside your own infrastructure, on your storage, so the traces never leave your perimeter. Whether that is workable depends on your stack and on the engagement, so it is a question for the first call rather than a promise on this page. Ask, and we will tell you straight whether it can be done for yours.
Who else touches them
Scoring a trace means a model reads it, so this is the question that matters most and it has three honest answers depending on how your engagement is set up.
- Your own model account, wherever possible. This is what we propose first. The judge runs against the model account you already have, under terms your organisation has already reviewed, so no new model vendor sees your traces and your security team has no new model contract to read. It does need a scoped key, or for the scoring to run on your side, and that is the one piece of access this arrangement asks for. Storage is a separate question, answered in the third bullet.
- Our model accounts, when you would rather we supplied them. Those are with Anthropic and OpenAI. Both state that inputs sent through their APIs are not used to train their models by default, and we do not opt in to anything that would change that. We will tell you which one an engagement uses before it starts, and we will use the other if your organisation has a view.
- A major cloud provider, for compute and storage, under a data processing agreement. We will name it and give you the region on request. It is described rather than named here so that this page cannot quietly go stale if it changes.
Nobody else. No analytics on your traces, no third-party observability tool with a copy of them, no subcontractors, and nothing shared with another client or used as an example without your written permission.
What we never do with them
- We do not train anything on your data, and we do not let anyone else.
- We do not reuse your traces, criteria or labels on another engagement.
- We do not name you, quote you, or publish a figure about you without written permission. Every case study on this site is anonymous by default for that reason.
Having them deleted
Write to hello@kayzn.io and ask. We delete the traces and confirm it. You do not need to give a reason, and it does not end the engagement: the criteria and the labels are what the work runs on from that point, and they are already yours.
What this page does not claim
We are a two-person firm and this page is a description of practice, not a certification. If your review process needs a specific control, a questionnaire answered, or a signed agreement of your own, ask on the first call and we will tell you what we have and what we have not rather than finding out during procurement. Asking is faster than a pilot that stalls at legal.
This page covers traces you send us for an engagement. What this website itself collects about you as a visitor is a separate and much shorter answer, on the privacy page.
Last reviewed 24 August 2026