# Security & compliance

> How Kepler protects your data — encryption, access control, GDPR and PDPA.

_Collection: Workspace, Team & Billing (workspace-admin) — Kepler Help Center. Canonical: https://keplercrm.com/support/articles/security-and-compliance/_

## Access control

  - **Workspace isolation** — every record belongs to one workspace; only its members can access it. All API access is authenticated and workspace-scoped.

  - **Roles** limit what members can do (see [Roles & permissions](/support/articles/roles-permissions/)). Placement fee figures and the Placement Finance dashboard are restricted to owners and admins.

  - **Email privacy** is enforced per connected account, with three sharing levels and per-person grants (see [Email privacy & sharing](/support/articles/email-privacy-and-sharing/)).

  - **Files** (CVs, recordings, attachments) are served only via short-lived signed URLs to authenticated members.

## Two-factor authentication

Under **Settings → Security**, every member can set up an authenticator app (TOTP — Google Authenticator, 1Password, Authy or similar) with **Set up**, add a second device, or remove it.

Workspace admins additionally get a **Workspace policy** section on the same page:

  - **Require two-factor authentication** — members without a verified authenticator app are asked to set one up before they can use anything else in Settings.

  - **Member two-factor status** — who in the workspace is enrolled and who isn't.

Members who are not admins still see the workspace policy, read-only, so they know what's required of their account.

## Single sign-on

Kepler supports SAML 2.0 sign-in for an email domain, but it is **not self-serve**: Kepler configures the connection during onboarding. Send your identity provider's metadata URL and the email domain you want connected. Once a connection is live, an admin can turn on **Require single sign-on** under **Settings → Security**.

> **NOTE:** Kepler does not currently offer session-timeout controls, device management, IP allowlists or a self-serve audit-log view.

## Data protection

Third-party credentials Kepler stores on your behalf — mailbox access tokens and webhook signing secrets — are encrypted at rest with AES-256-GCM under keys held outside the database.

For everything else, Kepler's published privacy policy is the authoritative statement: it says data is encrypted in transit and at rest, that Customer Data is not used to train AI models, and that Kepler complies with the PDPA and applicable UK/EU GDPR. Refer to the current policy for its exact wording.

  - Payment details are held by our payment processor, not Kepler.

  - See [AI & data privacy](/support/articles/ai-data-privacy/) for how AI features handle workspace content.

  - Users with permission to delete activities can permanently remove a meeting's recording, transcript and minutes using **Delete meeting data**.

## What deletion does

  - **Candidates** are tombstoned: the record leaves active views, search and matching, and can no longer be edited, but its applications, placements, interviews, communications, files, notes, tasks and history are preserved for reporting attribution. The delete toast offers a 10-second **Undo**; after that, restoring a candidate is a support request.

  - **Contacts, companies, jobs and placements** are deleted outright, with related rows cascaded or orphaned at delete time. There is no restore for them — check before you confirm.

  - Permanent erasure of a tombstoned candidate is a privileged operation. Contact support.

## Getting data out

Any record list exports to **CSV or Excel** from its toolbar, filtered and column-shaped as you have it on screen. For a workspace-wide export, or an export in a specific format, contact support to ask about scope, format and timing.

## Data subject requests

  - **Lawful basis & consent** — track candidate consent with a custom field (e.g. a "GDPR consent" checkbox with date) and filter on it for compliance reviews.

  - **Subject access & erasure** — a candidate's record consolidates their data (profile, documents, communications) for access requests. Contact support for a subject-erasure request, privileged permanent deletion or bulk compliance operations.

  - **The public portal** collects only what applicants submit, protected against abuse (rate limiting, honeypot), and never exposes internal data.

## Your part of the bargain

  - Remove leavers from the workspace promptly.

  - Use conservative email sharing for mailboxes containing non-work content.

  - Tell meeting participants when the [Note Taker](/support/articles/ai-note-taker/) is covering a call, per local law — especially Zoom calls, where capture is native and no bot appears.
