Loading published entries
KugelAudio
KugelAudio is the European speech platform for teams that put voice AI into production. Natural text-to-speech in 26 languages, developed and hosted in Europe, fully GDPR compliant.
Loading published entries
Loading published entries
Published descriptions of the controls we operate, grouped by area. Each entry states what the control covers and when the description took effect.
15 published entries
Customer traffic is served over TLS 1.2 or higher. The connection is terminated directly on KugelAudio ingress; no TLS-terminating CDN or reverse proxy sits in front of it, so no third party sees decrypted audio or text.
Effective since
Every credential used to deploy or run the service is stored encrypted with SOPS and age. Plaintext credentials are not committed to version control and not held in CI configuration.
Effective since
Each service authenticates to production datastores with its own credential. Shared logins are not issued, so access can be withdrawn for one service without rotating the others.
Effective since
Changes reach production through the GitOps pipeline, which applies the reviewed and versioned state to the cluster. The deployed state is therefore always a state that exists in version control.
Effective since
Production changes are made through pull requests that must pass the automated test and build gates before they can be merged and deployed.
Effective since
Dependencies are monitored automatically for known vulnerabilities and raised as updates against the repository. Runtime errors and performance regressions are collected in an error monitoring system that receives technical logs only, never audio or text payloads.
Effective since
Customers can report failures, incidents and concerns through the in-product messenger or by email, and each report reaches a named owner.
Effective since
Technical documentation for integrating and operating the service is published and versioned alongside the product, so customers can verify behaviour against a written reference.
Effective since
Changes to agreements, the subprocessor register and control descriptions are published in this trust center as dated update entries, and contract contacts are notified of material changes.
Effective since
Customer content is never used to train or fine-tune models. This holds for input text, generated audio and voice references alike.
Effective since
Content data — text, audio, prompts and transcripts — is processed transiently in memory and deleted on completion of the request. Account data, technical metadata and statutory billing records are retained as described in the AVV. Voice references are explicitly outside this scope and are governed by their own storage and deletion rules.
Effective since
Input text and generated audio are processed and stored exclusively in configured EU regions of the providers listed in the subprocessor register. Under EU-Only Hosting, providers established outside the EU or with a non-EU parent are not engaged at all.
Effective since
Voice references are held in S3-compatible object storage operated in the EU by the providers named in the subprocessor register, and are not copied to storage outside it.
Effective since
On termination, customer data is deleted or returned as provided for in the AVV, within the period the contract sets.
Effective since
Which algorithms are used for data in transit and for secret storage, and who may hold the decryption keys, are defined rather than left to each service to decide.
Effective since