Security and data handling¶
Kiwi uses organizational sign-in, resource ownership, and scoped tool access to control who can use data and capabilities. Those controls do not mean that every request stays inside Kiwi: models and some tools call other services to do their work.
Use this page to decide what to share, which capabilities an agent should have, and who should own a reusable resource. It describes product behavior, not a replacement for your organization's security, privacy, records, or client-data policies.
When data leaves Kiwi¶
| Capability | What may be sent | Destination or purpose |
|---|---|---|
| AI model | Your prompt, relevant conversation context, agent instructions, and selected file context | The configured model provider, to reason and respond |
| Web tools | Search terms or requested public URLs | Search and website services, to find or read public information |
| Code sandbox | Generated code, selected input files, and selected skills | A hosted execution sandbox, to compute results and return files |
| Media tools | The generation or edit prompt and selected source media | Media Studio, to create, edit, or caption media |
| MCP connector | Tool arguments and task data needed by that tool | The external MCP server and the system behind it |
| File processing | Uploaded file content needed for extraction, captioning, or search preparation | Configured enterprise processing and model services |
| Skill import | Content imported from a public repository | Safety scanning; semantic checks may use an AI model |
| Operational telemetry | Request metadata and bounded, redacted previews of model and tool activity | Restricted monitoring services, to diagnose failures, performance, and usage |
Turning web search off stops the agent from using Kiwi's public-web search and scraping tools for that conversation. It does not stop calls to the selected model, Media Studio, code execution, assigned MCP tools, file-processing services, or operational telemetry.
Only grant the tools needed for the task. If data must not reach a particular service, do not rely on the web-search setting; choose an approved model and remove the corresponding tool or connector from the agent.
What Kiwi stores¶
- Conversation history is stored by session so you can continue later.
- Uploaded files and extracted content are stored for Library use and retrieval.
- Generated and edited media is stored as a Kiwi file and can be returned through a time-limited signed link.
- Agent, Skill, collection, and connector configuration is stored so it can be reused and shared according to its access rules.
- Connector credentials are encrypted at rest; plaintext credentials are not returned after storage.
- Operational records support monitoring, diagnosis, and platform reliability. Telemetry can include bounded prompt/response and tool-input/output previews. Sensitive key names and protected credential values are redacted, but users should still avoid placing secrets in prompts or ordinary text fields.
Retention and deletion obligations depend on the deployment and applicable organizational policy. Contact the Kiwi team or the relevant data owner when you need the policy for a particular data class or client engagement.
Roles, ownership, and sharing¶
- Sign-in uses organizational SSO. Access to a resource then depends on its visibility, membership, and the action being performed.
- Private agents, Skills, collections, and connectors are controlled by their owners and members. Being an administrator does not automatically reveal private resource content.
- Owners manage private-resource membership. Kiwi prevents removal of the final owner.
- Public or platform-wide changes carry greater impact. Publishing agents uses an administrator or designated publisher role; public Skills, public connectors, shared connector credentials, and the model catalogue require administrator permissions for relevant changes.
- Access to an agent does not automatically grant access to every file, Skill, or MCP tool it references. Kiwi rechecks requester access as the run is resolved.
Before you send or share¶
- Confirm that the information is approved for the selected model and every enabled tool or connector.
- Remove secrets, credentials, unnecessary personal data, and unrelated client material from prompts and attachments.
- Use the narrowest agent tool set and resource membership that can complete the task.
- Check external-service terms and data handling before approving an MCP connector.
- Review generated text, analysis, code, and media before using or publishing it.
- Share stored files and signed links only with intended recipients.
If you suspect inappropriate access, credential exposure, or sensitive-data leakage, stop using the affected resource and contact the Kiwi team through your approved support or security channel.
Related: Connectors and MCP · Media · Skills · FAQ