Security & Trust
How Kiyomi protects your data. Last updated: July 2026.
Privacy and security are not a feature we added to Kiyomi. They are the reason it exists. Most AI tools work by shipping everything you type to someone else's cloud. Kiyomi is built the opposite way, and this page is the specific, honest account of how.
Your work is never sent to a third-party AI
Your chats, code, and files are processed by Jah on infrastructure RMDW owns and controls. They are not sent to any third-party AI cloud such as OpenAI, Anthropic, or Google, they are not sold or shared, and they are not used to train any model. That is the whole point of the product.
Where your data lives, and who holds the keys
The hosted version of Kiyomi runs on private hardware RMDW operates directly, not resold space in a hyperscaler. For private, on-premise deployments, Jah runs on yourhardware, inside your own building, so your data never leaves your control at all. When there is no third party in the loop, there is no third party to trust. That is a stronger guarantee than any cloud vendor's compliance stamp, because those stamps exist precisely to reassure you about data you handed to someone else.
What we store, and how to delete it
To run your account we store only what the product needs: your email (for sign-in), your conversation history (so you can return to it), and your plan and usage counts (for billing and limits). That history lives in our own managed database, not a third-party AI service, and you can delete any conversation or your entire account at any time.
Encryption
Access tokens and secrets are encrypted at rest with AES-256-GCM. Our managed database encrypts stored data at rest and takes automated backups. All traffic between you and Kiyomi is encrypted in transit over TLS.
Payments
Payments are handled by Stripe. We never see or store your full card details. Stripe processes them directly and we keep only a customer reference and your subscription status.
The model behind Jah
Jah is built on proven, openly-published foundation models, adapted and hosted privately by RMDW. It is not a black box and it does not call out to an external AI service to do its work, so your prompts stay on our infrastructure. You get frontier-grade capability without shipping your data to a frontier lab.
Reliability
We watch Kiyomi around the clock with automated health checks and real-time alerts, the service recovers automatically after a restart, critical hardware runs on battery-backed (UPS) power, and account data lives in a managed database with automated backups. We treat uptime like production, and we are candid that Kiyomi is run by a focused independent team rather than a faceless data center.
Who builds and secures it
Kiyomi is built and operated by Richard Echols, a mathematician and data engineer with an enterprise background (including years at IBM) and a CompTIA Security+ certification. Security is designed into how the product is built, not bolted on afterward.
Formal certifications, honestly
We do not yet hold third-party attestations such as SOC 2 or ISO 27001. Those frameworks are built to reassure customers about vendors that hold other people's data in a shared cloud at scale, and we pursue them as we grow into regulated clients in fields like healthcare, legal, and finance. For private, on-premise deployments the question is largely moot: your data never leaves your control, which is the exact outcome those audits exist to verify. We would rather tell you plainly where we are than imply a badge we have not yet earned.
Report a security issue
Found something, or have a security question? Email richardechols@rmdwllc.com. We take responsible disclosure seriously and will respond quickly.
This page is provided in good faith and describes our current practices, which we improve over time. It is not legal advice or a contractual warranty.