Security & compliance overview
How KMP protects data moving through your pipelines.
Encryption
All API traffic requires TLS 1.2+. Connector credentials are encrypted at rest and are never returned in full by any endpoint after creation.
Credential handling
See Authentication for API key handling, and Connectors endpoint for connector credential rotation.
Least privilege
We recommend scoping every source connector's credentials to read-only access, as described in the Connecting a data source guide.
Data residency
Events are processed in the region your workspace was created in and are not replicated across regions by default.
Reporting a vulnerability
Contact the team through Support / Contact — do not file security reports as public issues.