Security & compliance overview

How KMP protects data moving through your pipelines.

Encryption

All API traffic requires TLS 1.2+. Connector credentials are encrypted at rest and are never returned in full by any endpoint after creation.

Credential handling

See Authentication for API key handling, and Connectors endpoint for connector credential rotation.

Least privilege

We recommend scoping every source connector's credentials to read-only access, as described in the Connecting a data source guide.

Data residency

Events are processed in the region your workspace was created in and are not replicated across regions by default.

Reporting a vulnerability

Contact the team through Support / Contact — do not file security reports as public issues.