We obsess over security so you don’t have to.
KKHS Assist lives in your WhatsApp, with access to your conversations and the tools you connect. Protecting that is the foundation everything else is built on — here’s exactly how it works.
Your data stays yours.
No pooling, no prying eyes, no quiet collection. Four guarantees that hold for everything you put in.
Fully isolated sessions
Every session runs in its own sealed environment. Your data is never pooled with anyone else's and never leaves that environment — the only thing that touches it is your own agent, acting on your instructions.
Encrypted with per-user keys
From the moment you sign in, your data and logs are encrypted with keys derived via HKDF from a master key and a unique per-user salt. Keys are never left sitting somewhere to be stolen, and identical data looks completely different once encrypted for different users.
No activity logs. No telemetry.
Nothing you do is quietly collected or sent back. The single exception is feedback you choose to give — which is logged and visible to you, so you always know what was sent and when.
Never used to train AI
We explicitly opt out of all model training on customer data — ours or anyone else's. What you put in is used to run your assistant, and nothing more.
It only ever does what you allow.
WhatsApp, calendar, files, email — your agent reaches only what you explicitly connect, and uses it only to carry out what you ask.
Read-only by default
Across all your chats, your agent can look but never sends anything on its own. Mark any chat as sensitive or off-limits and it won't even read it.
It confirms before it acts
Anything sent or changed on your behalf is shown to you for approval first. Money, payments, and binding promises always come back to you — even in autonomous mode.
Connect and disconnect anytime
Link a service when you want the capability, unlink it the moment you don't. Disconnecting immediately stops all future access — nothing stays connected without your say-so.
Delete anything, anytime
Remove specific data, clear what your agent remembers, or delete your account entirely. Control over what KKHS Assist holds never leaves you.
Three modes. You set the dial.
Every chat has a mode that decides when — if ever — your assistant acts on its own. Your self-chat stays your private workspace; these apply to everyone else's chats.
Completely out
Your assistant stays out of this chat entirely. It never reads and never replies — not even when you summon it with /kk.
Steps in when asked
The default for other people's chats. Your assistant only acts when you summon it with /kk, and stays quiet otherwise.
Handles it for you
For chats you hand over deliberately. It reads new messages and replies on its own until you tell it to stop.
Draft-first, by default
Before messaging anyone else on your behalf, KKHS Assist shows you the draft in your self-chat and waits for your OK — you approve with a tap. And auto-engagement in chats you haven’t switched on stays off until you deliberately enable it.
Defended in depth.
Every connection to an outside tool is a possible way in. We treat each one as hostile until proven safe — and then keep testing.
Prompt injection, contained
Malicious instructions hidden inside ordinary-looking content are the main threat to any agent. Yours runs in a secured runtime with strict safeguards against unauthorised prompts, scripts, skills, and tool use.
Every skill vetted
Each skill, plugin, and connection is vetted against injection and abuse before it's ever allowed to run in your environment.
Independently tested and audited
Regular vulnerability testing hunts for weaknesses before anyone can exploit them, and standards like ISO/IEC 27001:2022 hold our controls to an external benchmark — not just our own judgment.
