For those evaluating Kate

Where the data sits, how it is protected, what we don’t do.

This page is for the people who have to sign off: IT, security, whoever signs. No vague formulas: where the data sits function by function, the commitments we make, and the things Kate does not do today.

The chain

Every piece, and where it sits.

Kate is not a single block: it is five functions, each with a job and a place. Everything that holds or touches your notes is in the European Union. We don’t publish supplier names here: they are part of the data processing agreement and we give them to you in writing on request, even before you sign.

FunctionWhat it doesWhere
Database and archiveNotes, links, audiences, permissions, history, attachments and photosEuropean Union
Application and APIThis is where the code that touches your notes runs. Calls to your systems also leave from here, with a fixed IP addressEuropean Union
Semantic searchTurns notes into vectors, to find the right onesEuropean Union
Answer generationWrites the text from the retrieved notesEuropean Union
Network and public pagesDNS, protection and delivery of this websiteNone of your content

Commitments

What does not happen to your data.

No training

Model providers do not use your questions, your notes or the answers to train their models. It is written into the contracts we sign with them.

The model is not your archive

The model receives the relevant notes at the moment an answer is needed, and does not keep them. The archive is the database, and it is yours.

Audiences do not mix

The perimeter is enforced by the database, not by the prompt. Someone without access to an audience does not see those notes, not even inside an answer.

Nobody here looks in silence

To assist you, a person at Thingz must open a support session: with a stated reason, an expiry, and a trace that stays in your logs.

Diagnostics are anonymous

Administrators see which notes were used and how confident Kate was, without the author of the question. It is there to understand answers, not to watch people.

Fixed outbound IP

Kate’s calls to your systems leave from a single address, which you can allowlist on your firewall.

GDPR

Who is responsible for what.

The client company is the data controller: it decides what goes into Kate, who sees it and who can change it. Thingz is the processor and acts on your instructions. The suppliers performing these functions are sub-processors: the full list, with each name and location, is attached to the agreement and provided on request.

AgreementWe sign a data processing agreement (DPA) before we start.
TransfersProcessing happens in the EU. Where a supplier is headquartered outside the EU, standard contractual clauses apply.
ExportNotes can be exported at any time, in a readable format. The knowledge is yours.
DeletionAt the end of the relationship the data is deleted on your request, attachments included.
Sub-processorsIf a supplier changes, we tell you before, not after.

Integrations

Today: web and API. Everything else is built on the API.

We would rather say it plainly than let it be assumed. Kate is used from the web and queried through the API. Any other channel — Teams, a phone system, an intranet, an internal app — is built on the API, by your IT department or your technology partner: the knowledge stays in one place, no copies are made. We concentrate on the product.

WebAvailable. Chat, review, knowledge management, administration.
APIAvailable. The same governed knowledge, queried from your systems.
Sign-in with your company identityNot available today: access is by email invitation. It is on the roadmap, and the principle is that identity stays where you already administer it — so your access policies and two-step verification apply to Kate too, and someone who leaves the company loses access the moment they lose the account. We will use the integration standards, not an integration built for one specific vendor.
Teams, Slack, phone systems, intranetBuilt on the API, by you or your partner. They are not connectors we supply.
Your existing document sourcesDocuments are uploaded. There is no automatic import from your archives, and it would not remove the work that matters: a note becomes knowledge when one of your people confirms its topic, audience and links. That confirmation is what separates a governed answer from one fished out of the files.
Local modelsNot available today, but possible: the architecture keeps the model separate from everything else and the provider is configurable. We follow the evolution of models that can run inside your own infrastructure and will adopt them when they are good enough.

Migration

Who creates the notes, and how much work it really takes.

Kate reads your documents and proposes notes, split by topic, with suggested tags and links. But a note becomes knowledge when one of your people confirms it: that is exactly the point of the product, and it means the start is not free.

What we doThe onboarding included in the setup fee: we build the first knowledge together, on your real documents.
What we need from youA knowledge owner: someone who owns the notes and closes the reviews. Without one, Kate governs nothing.
How longIt depends on the volume and the state of the documents. We tell you after seeing yours, not before.
AfterwardsYou do not start over: when a procedure changes you update the note, not the 60-page file.

Whatever you don’t find here, just ask.

Request a founding seat