Sign-in
- Methods: email and password, Google, GitHub, or SSO with OIDC or SAML 2.0 on the Enterprise plan.
- Require SSO turns off every other sign-in method for your verified domain. The workspace owner keeps password access.
- Two-factor authentication: turn it on under Profile → Security → Two-Factor Authentication. It uses an authenticator app code, with backup codes.
- Passwords are stored as bcrypt hashes, never in plain text.
- reCAPTCHA v3, when enabled, protects sign-in, registration and password reset, and requests made with a public client key. The widget handles the token for you.
Keys
| Key | Where | Notes |
|---|---|---|
Public client key (kl_pk_…) | Knowledge base → Integrations → Client Keys | Safe in a web page. Set Allowed origins. |
Secret client key pair (kl_ci_… / kl_cs_…) | Same place | For your server only. Skips the origin check and captcha. |
Workspace API key (klk_…) | Settings → API Keys | Covers the whole workspace. |
Restrict public keys to your domains
Add your site under Allowed origins, for example
https://docs.example.com. https://*.example.com covers subdomains. A key with no allowed origins works from any website.429.
Control who sees what
- Roles: owners and admins manage the workspace. Other members get access per knowledge base. See Roles & Permissions.
- Internal knowledge bases have no public surface. No client key works with one, so only signed-in team members can ask it questions.
- Restricted documents are hidden from public surfaces: the widget, public API, form deflector, helpdesk replies and public MCP. Team members in Ask still see them. To make a source’s documents restricted, set Visibility to Restricted when you add it. For a source you already have, set Configuration → Indexing → New documents to Restricted. That applies to documents indexed afterwards.
Your data
- AI providers: to index your content and answer questions, Kelu sends your content and readers’ questions to its AI model providers. With Bring Your Own Model, answers run on your own provider account instead.
- Personal data: turn on PII masking before you index tickets, chat history or uploads.
- Retention: set a retention window or zero data retention.
- Readers: the widget identifies a reader with a random ID stored in their browser. No name or email is needed to chat. Analytics store no reader IP addresses.
- Stored credentials: keys and tokens you give Kelu for sources, bots, helpdesks and AI providers are never shown again after you save them. AI provider keys, source credentials, helpdesk credentials and an Intercom agent app’s token are also encrypted with AES-256-GCM.
- Kelu staff access: when Kelu staff open a trace or sign in as a user to help you, the access is recorded in Kelu’s internal audit log.
Activity Log
Settings → Activity Log records sign-ins, registrations, password changes, member invites and removals, role changes, ownership transfers, workspace and knowledge base changes, and workspace API key changes. Owners and admins can read it.Answer safety
- Grounded answers: when your sources do not cover a question, the model gets no content and no citations, so it says it cannot answer instead of guessing.
- Citations: each answer links to the documents it used.
- Untrusted content: the model is told to treat instructions found inside your documents as content, not as commands.
Signed webhooks
Kelu checks the signature on every incoming webhook:| Source | Check |
|---|---|
| GitHub source sync | X-Hub-Signature-256 (HMAC-SHA256) |
| Slack | Slack signing secret, requests older than 5 minutes refused |
| Microsoft Teams | Bot Framework token |
| Helpdesks | The platform’s own signature (Zendesk, Intercom, Front), or an HMAC with a secret Kelu generates |
| SAML sign-in | XML signature against your IdP certificate |
X-Kelu-Signature: sha256=<hex>, an HMAC-SHA256 of the body, when you set a secret.
Network
- The crawler never fetches cloud metadata addresses.
- A Bring Your Own Model address must use https and a public address.
- If your site is behind a firewall, allow the crawler’s IP address shown under Settings → IP Whitelist.