Privacy and security

Use AI on confidential searches without losing control of the data.

Kaiya is built for sensitive mandates, candidate conversations and firm knowledge. It gives authorised users a controlled workspace for executive search AI: customer data is isolated, chats stay private to the user, and customer content is never used to train models.

Security & privacy

Key facts for confidential search work.

Model training

Customer conversations, CRM data, search indexes and mandate materials are not used to train models by Kaiya or its approved AI model provider.

Customer separation

Kaiya keeps each customer's data separate, including customer-specific Invenias search indexes.

Hosting and encryption

Kaiya backend services run on AWS infrastructure. Stored data is encrypted where Kaiya controls storage, and data moves between systems over encrypted connections.

Access

Users sign in with their organisational Microsoft account, and customers choose which users and integrations are enabled.

Invenias updates

Kaiya updates Invenias records only when an authorised user asks it to. Your firm controls what changes.

Unmanaged AI accounts

Unmanaged AI puts confidential search data outside firm controls.

ChatGPT, Claude and other general AI tools can be useful. The question for executive search is different: should confidential client, candidate and CRM data go into an unmanaged AI account outside your firm's controls?

A useful external analysis from Simpliant explains why GDPR compliance depends on the use case, the business processing arrangement, the legal basis, processor terms and transfer safeguards. Read the article.

Privacy question General AI chat Kaiya

Processing arrangement

If users paste personal data into unmanaged accounts, the firm may not have a processor arrangement, approved purpose or transfer review for that use.

Kaiya is supplied under customer terms and a Data Processing Agreement for service delivery and customer instructions.

Customer boundary

The tool is not built around your firm's private workspace, CRM indexes, mandates and approved search workflows.

Customer data, conversations and Invenias search indexes are isolated per customer.

Operational control

Policy often depends on telling users what not to paste into the interface.

Kaiya is designed around authorised sources, customer instructions, review and retention controls.

Model training

The buyer must check whether prompts and outputs can be used to improve the provider's services.

Kaiya uses contractual provider arrangements that do not permit customer data to train models.

Policy-backed controls

Security and privacy controls are built into the workflow.

The customer terms, Data Processing Agreement and Acceptable Use and Security Policies are reflected in how Kaiya handles sign-in, customer data, approved sources and human review.

Identity and access

  • Users sign in with their organisational Microsoft account
  • Customers choose which users and integrations are enabled
  • Users should only access Kaiya through approved accounts and tools
  • Suspicious activity or a suspected account compromise should be reported promptly

Customer data

  • Kaiya runs on AWS-hosted infrastructure
  • Each customer's data is kept separate from other customers
  • Invenias search indexes are kept separate for each customer
  • Stored data is encrypted where Kaiya controls storage
  • Data moves between systems over encrypted connections

Review before sharing

  • Your firm remains in control of the personal data it asks Kaiya to process
  • Kaiya processes personal data only for customer instructions and service delivery
  • Approved providers are used only where needed to complete the request
  • People must review sensitive or high-impact outputs before relying on them

Request path

Sensitive work stays inside a controlled customer path.

Kaiya is not a shared consumer chat window. It connects authorised users, customer systems, customer-specific search indexes and approved providers in a controlled workflow.

Request path Microsoft login to customer workspace
  1. User signs in through their organisational Microsoft login.
  2. Requests reach Kaiya over encrypted connections.
  3. Kaiya runs on AWS infrastructure, with each customer's data kept separate.
  4. Customer search indexes, including Invenias indexes, are kept separate for each customer.
  5. Approved AI and search providers are used only as needed to complete the request.
  6. Chat history is available for review and resumption inside Kaiya, then deleted automatically.

Frequently asked questions

Security questions worth asking early.

Use these points when deciding whether Kaiya fits the way your firm handles confidential searches.

Is Kaiya a secure, GDPR-ready AI tool for executive search?

Kaiya is built for executive search firms that need AI on confidential client, candidate and CRM data. It uses customer terms, a Data Processing Agreement, isolated customer data, approved providers, encrypted connections and human review to support GDPR-compliant workflows.

Why use Kaiya instead of ChatGPT, Claude or another general AI chat?

A general AI chat is not designed around your firm's customer terms, separate customer data, CRM indexes, authorised integrations and search workflow controls. Kaiya is built as a governed customer environment for executive search work.

Is customer content used to train models?

No. Customer conversations, CRM data, search indexes and mandate materials are never used to train models by Kaiya or its approved AI model provider.

Where is Kaiya hosted?

Kaiya backend services run on AWS infrastructure. Data stored by Kaiya is encrypted, and data travelling between systems uses encrypted connections.

How are conversations handled?

Conversations stay inside Kaiya's controlled customer workflow for review and resumption. They are never used to train models.

How is Invenias data handled?

Kaiya uses a dedicated Invenias service account to build and refresh search indexes. Each customer has a separate search index, and customer data is kept separate from other customers.

What do Kaiya's policies add?

The customer Data Processing Agreement sets out the role Kaiya plays when it handles personal data for a customer. In short: Kaiya processes data for service delivery and customer instructions, keeps it confidential, uses approved providers only where needed, supports breach and data-rights obligations, and handles return or deletion under the agreement.

Book a demo

Bring us your security questions and a live search workflow.

We will show how Kaiya handles client, candidate and CRM data in the workflow your team actually runs.