KiAlt

·Data Trust & Security
For MFDs & Distributors

Enterprise-grade security. Zero compromise.

KiAlt is a tool for MFDs — not a data business. Every piece of client information you bring into the platform stays under your control, is encrypted end-to-end, and is never used for anything beyond serving you.

✓ AES-256 Encryption at Rest
✓ TLS 1.3 in Transit
✓ Zero Data Monetisation
✓ No Third-Party Sharing
✓ DPDP-Aligned Architecture

Encrypted at rest

All client data stored with AES-256 block-level encryption

Encrypted in transit

TLS 1.3 on every API call — no plain-text transmission ever

Never sold or shared

We have no data-resale model. Zero. Contractually binding.

Isolated per MFD

Tenant-level data isolation — your data never touches another firm's

✗ We Never

Sell your clients' data to any third party — ever

Use your client portfolio data to train AI models

Share client identifiable information with AMCs, BSE, or any market participant

Use your data to cross-sell to your clients directly

Access your client data without an explicit, logged service request

Store raw CAMS/CAS files beyond the processing window

✓ We Always

Encrypt all client data at-rest (AES-256) and in-transit (TLS 1.3)

Keep each MFD's data in isolated, access-controlled tenants

Give you full ability to delete your data — including on request

Log all internal access to production data with time-stamped audit trails

Use anonymised, aggregated benchmarks only — never linked to a client

Align with India's DPDP Act (Digital Personal Data Protection Act) framework

Six Technical Pillars

01

Multi-Tenant Isolation

Each MFD firm is provisioned in its own isolated data partition. Row-level security policies ensure that no query from Firm A can ever surface data belonging to Firm B — even within the same database cluster.

Row-Level Security (RLS)
02

Encryption at Every Layer

All client PII fields (names, PANs, phone numbers) are encrypted before being written to the database. Even if a database dump were somehow obtained, the data would be unreadable without the encryption keys — which are stored separately.

AES-256 + Key Segregation
03

Zero Trust API Access

All APIs are authenticated using short-lived JWT tokens. No long-lived secrets are used. Every API call is validated against the requesting user's role and the MFD tenant scope before any data is returned.

JWT + Role-Based Access Control
04

Immutable Audit Logs

Every read and write operation on sensitive data generates a time-stamped, tamper-proof audit log entry. This includes internal KiAlt team access — we see only what we log, and every log is retained and attributable.

Append-Only Audit Trail
05

Right to Erasure

When you off-board or request data deletion, KiAlt runs a verified purge across all storage layers — primary DB, backups, and any derived caches. You receive a deletion confirmation. No shadow copies.

DPDP-Compliant Purge Workflow
06

Secure File Processing

Portfolio files (CAS Excel, CAMS PDFs) are processed in ephemeral compute environments. The raw file is parsed, structured, and immediately discarded — never written to long-term storage in its original form.

Ephemeral Processing · No Raw Retention

The Data Flow: Six Steps to Trust

01

Upload Initiated

Client-side, in your browser

The file is selected on your device. It's transmitted over a TLS 1.3 encrypted HTTPS connection to KiAlt's servers. No intermediary can intercept or read it in transit.

02

Ephemeral Parsing

In-memory, temporary

The file is loaded into a short-lived compute session. Relevant data (folio numbers, scheme names, NAVs, units) is extracted and structured. The original raw file is never persisted to disk.

03

PII Encryption

Before any database write

Personally identifiable fields — client name, PAN, mobile number — are encrypted using AES-256 with your tenant-specific encryption key before a single row is written to the database.

04

Tenant-Scoped Storage

Isolated by MFD firm

Structured data is stored under your MFD's isolated partition. Row-level policies prevent cross-tenant queries at the database engine level — this is enforced in code, not just in access rules.

05

Usage & Analytics

Anonymised only

If KiAlt ever uses portfolio data to improve benchmarks or scoring, it does so only on anonymised, aggregated signals. No client identity, no firm identity. Individual portfolios are never used as training data.

06

Deletion on Request

Full purge, confirmed

When you delete a client record or off-board entirely, a verified cascade purge runs across all storage layers. You receive written confirmation of deletion.

We are not in the data business. We are in the business of making you a more intelligent, efficient, trusted advisor.

Your client relationships took years to build. KiAlt exists to strengthen them — never to exploit the data behind them.

KiAlt · Investment Intelligence · For MFDs