> ## Documentation Index
> Fetch the complete documentation index at: https://developers.kardinal.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Data security and handling

> Hosting and compliance for delivery and end-customer data.

## What data flows through the API

Requests and responses commonly include operational data (addresses, time windows, vehicle capacities) and, when you choose to attach it, personal data about drivers and end customers — for example driver names, customer names, addresses, and phone numbers passed through `properties` fields on resources and orders (see the [`Properties`](/api-reference/plan/create-a-plan) schema). Kardinal does not require this data; you control what you send.

## Hosting and data location

The API is hosted in the EU, and so is your data. Additional regions may be added over time, since Kardinal relies on international managed cloud providers.

## Tenant isolation

Every access token is scoped to exactly one agency (`sandbox` or `production` for builder accounts) — see [Authentication](/guides/authentication). A token cannot read or write data belonging to another agency: a request for another agency's plan fails with a `404` and `code: NOT_FOUND`, exactly as if the plan didn't exist, so that the API never reveals whether another agency's data exists. There is no way to query across agencies with a single token.

## Encryption

All API traffic is encrypted in transit via TLS 1.3+. Data at rest is encrypted using AES-256.

## Data retention

Plans and their associated orders and resources are automatically removed one year after their last update. You can purge a plan immediately via `DELETE /plans/{planId}` instead of waiting for automatic removal.

Billing data is retained indefinitely, and audit logs for two months — neither can be purged on request, including via `DELETE /plans/{planId}`.

## GDPR

Kardinal acts as a data processor for any personal data you submit through the API; you remain the data controller. Contact [dpo@kardinal.ai](mailto:dpo@kardinal.ai) to request a Data Processing Agreement, or to forward a customer's GDPR rights request.

## Certifications

Kardinal does not currently hold SOC 2 or ISO 27001 certification, but is working towards SOC 2 Type II.

## See also

* [Authentication and API keys](/guides/authentication) — how a token is scoped to a single agency.
* [Limits and quotas](/reference/limits-and-quotas) — SLA and support commitments.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.