SECURITY AND GOVERNANCE

The answers your IT people will ask for.

There are two separate promises here and most vendors blur them. One is the platform your data sits on. The other is what KMS does inside your engagement. This page keeps them apart, because they carry different evidence and different limits.

Written for the person who has to sign off, not for the person who has to be sold.

THE PLATFORM

How your data is held.

Encrypted in transit and at rest

TLS while it moves, strong encryption while it sits.

Your tenant is isolated

Logical separation from every other customer. Dedicated single-tenant instances are available on higher tiers.

Certified infrastructure, and an honest word about the platform

The platform runs on cloud infrastructure certified to ISO 27001 and SOC 2. The platform itself is at SOC 2 Type II readiness and aligned to GDPR. We say readiness because that is what it is — the certification is being pursued, not held.

Your content is not training data

Contractual no-training and zero-retention terms with every model provider in the chain. A Data Protection Officer is appointed.

WHAT YOU CAN CONTROL

The controls, and the tier each one starts at.

Every plan

Encryption in transit and at rest. Multi-factor authentication. Role-based access control.

Standard and above

Regional data residency — EAME, AMER or APAC.

Premium and above

A single-tenant dedicated instance, rather than logical separation inside a shared one.

Enterprise

Customer-managed encryption keys that you hold. Single sign-on via SAML 2.0 or OIDC. Private connectivity that bypasses the public internet. Exportable audit logs.

One thing to know before you start free.

The entry tier is hosted in the EU with no residency choice. If where the data sits matters to you from the first day rather than the first contract, tell us and we will start you a tier up.

IN A KMS ENGAGEMENT

What we do, separately from the platform.

Read-only by default

We connect read-only. The Mates query your systems; they never write back to them.

Nothing executes without a person

Every recommended action is costed and queued for a named approver. The system proposes; a human decides.

You evaluate us on exported data

Nothing live is connected to find out whether this works. Live connections come after you have decided, not before.

PDPA is handled in the engagement, not claimed by the platform

The vendor's security documentation is GDPR-framed and does not address Singapore's PDPA. We will not pretend otherwise. PDPA obligations are scoped and agreed in writing with you, before any patient-level data moves.

WHAT WE WON'T CLAIM

Three things we're careful about.

We are not SOC 2 certified

The infrastructure beneath the platform is. The platform is at readiness. Those are different things and we will not blur them.

Residency is regional, not national

You can require that your data stays in APAC. You cannot yet require that it stays in Singapore.

There is no on-premise option

The platform is SaaS only. If your policy requires software running inside your own data centre, we are not the right fit, and we would rather say that in week one than week nine.

Ask for the detail.

Email ask@kms-world.com and we will send the architecture summary and the data processing agreement, and put you on a call with the people who built the deployment — not a sales engineer reading a datasheet.

KMS

Knowledge Management Solutions
Singapore-based. Deployed across Southeast Asia.
Master Reseller for Allmates.ai across Southeast Asia.

Unlocking the Power of AI for Analytics and Automation.

Get in touch

ask@kms-world.com


© 2026 KMS — Knowledge Management Solutions. All rights reserved.