
At 1KE, we recognise that your customer conversations and the solutions built from them are among your firm's most valuable assets and often involve sensitive, NDA-protected information.
That's why 1KE has been engineered so you can maintain customer confidentiality and safeguard your solution IP, letting your team close more pipeline with confidence and assurance.
1KE operates independent regional deployments on Google Cloud. Customer records, uploaded files, meeting transcripts and generated outputs are stored in the regional deployment selected for your organisation. AI inference may be processed outside that region depending on the model provider and endpoint used.
AI for inference only - not training.
Your content is sent to approved model providers only to produce the requested outputs. It is not used to train their models. Limited provider-side operational retention may apply under the relevant provider’s terms.
Data is encrypted in transit and at rest, with an additional encryption layer for stored integration credentials. High-impact administrative actions are recorded in an append-only audit log.
Invite-only accounts, multi-factor authentication and deal-level permissions ensure users can access only the work they are authorised to see.
1KE runs entirely on Google Cloud Platform and is deployed as independent regional stacks. Each regional deployment has its own cloud project, database, file storage and identity tenant. Customer records, uploaded files, meeting transcripts and generated outputs are stored in the regional deployment selected for your organisation and are not replicated into another 1KE regional deployment.
Australian customers are served from our Sydney deployment. When an AI-powered feature is used, the content required for that request is sent to an approved model provider. That processing may occur outside the selected region depending on the provider and endpoint used. Generated outputs are returned to and stored in the customer’s regional deployment.
US customers are served from a dedicated US deployment operating on the same regional-stack model.
Each 1KE customer operates within a separated organisation workspace. Every record carries your organisation's identifier, and that boundary is applied automatically on every operation - enforced in code rather than by configuration, so every feature, including new ones, inherits it by default.
No. 1KE is purpose designed to prevent cross-customer reuse of sensitive deal intelligence. Deals, uploaded documents, requirements, solution assumptions and proposal artefacts stay scoped to your organisation.
This extends to AI - prompts are assembled only from your organisation's data, so your customers' material and your solution IP cannot surface in another firm's workspace or outputs.
Authentication is handled by Auth0, and every request is validated before anything else runs:
MFA at every sign-in, with supported factors including authenticator applications, passkeys and hardware security keys; SMS, voice and email authentication are not offered
Invite-only accounts - self-service signup is disabled
Deal-level access - a deal is visible only to the users who created it, are assigned to it, or are on its team
Role-based permissions - administrative functions are gated by role
You can configure your users to only see what they are authorised to work with.
Yes. 1KE's authentication is built on Auth0 and can support enterprise identity requirements such as SSO and advanced identity protection controls where required. MFA options include authenticator apps and passkeys secured by biometrics or hardware security keys, with single-use recovery codes available for account recovery.
Encryption - data is encrypted in transit and at rest; all traffic runs over HTTPS, and the database refuses any unencrypted connection.
File storage - files are held in private regional cloud storage and logically scoped to your organisation. Public access is prevented, and every download uses a time-limited signed link issued only after authentication and organisation checks.
Uploads - validated for size, type and content, and never executed by the platform.
Together, these controls protect against unauthorised access to your files and data.
1KE works with selected AI model providers, including OpenAI, Google and Anthropic. We continually evaluate providers and may update this selection over time. 1KE uses AI for workflows such as requirement extraction, meeting briefs, solution generation and proposal creation.
These workflows are scoped to your organisation. Customer content is sent to an approved model provider only to produce the requested output and is not used to train any model. Limited provider-side operational retention may apply under the relevant provider’s terms. For example, OpenAI may retain API abuse-monitoring logs containing prompts and responses for up to 30 days. 1KE configures OpenAI requests so they are not retained as retrievable application state.
Meetings are captured by a notetaker bot that joins the call under a visible name, so participants can see it is present. Transcripts are returned to 1KE through a signed webhook that is cryptographically verified before any content is accepted. Accepted transcripts are stored in the customer’s regional deployment.
Customers are responsible for ensuring that their users obtain all required participant consents before recording or transcribing a meeting.
Customer records and files are retained for as long as they remain in the platform. Temporary working files are removed automatically under lifecycle rules. Database backups are retained for up to seven days, after which they expire under the applicable backup policy.
Model-provider operational retention is separate. For example, OpenAI may retain API abuse-monitoring logs containing prompts and responses for up to 30 days under its standard API terms.
CRM and third-party integration credentials are encrypted at rest, with an additional layer of AES-256-GCM encryption applied before they are stored. Integrations preserve organisation-level boundaries, so your systems and records remain connected only to your 1KE account.
1KE uses selected providers to deliver cloud hosting, identity, meeting transcription, AI inference, notifications, monitoring and optional integrations. These include Google Cloud, Auth0, Attendee, OpenAI, Redis Cloud, Sentry and selected notification and integration providers. Each provider receives only the information required to perform its service. A more detailed provider list is available as part of a customer security review.
Yes. 1KE can support deeper security review for customers with specific requirements around data residency, identity, access control, AI processing, integration security or operational governance.
Please raise questions or requirements with our team at hello@1KE.ai.