trust & security
Security & Trust
kulla is built to be deployed inside your walls and to prove what it did. Security isn't a bolt-on; it's how the framework is constructed.
How kulla protects your data
- Customer-hosted by design. Your encrypted agent memory lives on infrastructure you own. It never lands on a vendor's servers, and it never enters anyone's training set.
- Deny-by-default permission gateway. Every agent action is gated by an operator-set level: deny, ask, notify, or auto. Nothing runs that you didn't allow.
- Tamper-evident audit trail. Every decision and action is written as it happens, timestamped and (in kulla Enterprise) hash-chained, exportable and independently verifiable.
- Prompt injection closed at the framework layer. Guardrails are enforced by the system, not patched at the model.
- Bring-your-own model keys. You choose the provider; credentials and data stay under your control.
Operational maturity
- MOMUS DEV, LLC operates a documented Cyber Security Awareness Program (v1.0), attested by all founders.
- All kulla intellectual property is owned outright by MOMUS DEV, LLC, with clean provenance and no third-party encumbrances.
- Published Terms of Service and Privacy Policy.
Enterprise artifacts
The following are available to enterprise buyers and procurement teams on request: Data Processing Agreement (DPA), Master Services Agreement (MSA), Security Exhibit, and Content Moderation & Takedown Procedure.