What data governance should you require from a chemical AI vendor?

Demand Governance From Your AI Vendor.

Share

Require four commitments from a chemical AI vendor: a written policy that your data never trains the vendor's models, complete data isolation between customers, SOC 2 Type II and GDPR compliance evidenced by audit reports, and the right to export and delete your data when the contract ends. Kimia, a chemical intelligence platform, publishes all four on its security page.

Your data never trains the vendor's models

The first requirement is a training commitment in writing: the proprietary product data, formulations and customer information you load into a platform must never train the vendor's models. Kimia states this on its security page as "Your data never trains our models". Kimia's chemical intelligence is built on public chemical data. What your organisation adds is used solely to improve your own experience, and learnings never leak to other customers or external systems.

In practice: a specialty adhesives supplier loads hot-melt formulation records and application guides into Kimia. A competitor licensing the same platform gains nothing from that. The supplier's data improves answers inside its own workspace only, and no model shared across Kimia customers ever learns from those formulations.

Complete data isolation, with export and deletion rights

Ask where each customer's data sits relative to every other customer's. The answer you want is complete data isolation: every customer operates in a fully isolated workspace, with data, outputs and activity separated from every other account. Kimia runs this way, with no cross-contamination and no shared learning between workspaces. Governance also covers the exit. Kimia customers can export their data at any time, and on cancellation it is deleted from Kimia's systems upon request.

In practice: two distributors carry overlapping polyurethane dispersion portfolios and both use Kimia. Workspace isolation means neither sees the other's pricing, purchase history or enquiry records. A question answered in one workspace draws only on that distributor's own documents and data, never on a shared index.

SOC 2 Type II and GDPR, evidenced by the report

Certification claims need evidence. SOC 2 Type II attests that a vendor's controls operated effectively over an audit period, where Type I only assesses their design at a single point in time, so require Type II specifically and read the report. Kimia is SOC 2 Type II and GDPR compliant, with enterprise authentication and encryption as standard, and runs on SOC 2 and GDPR-certified infrastructure partners including AWS, WorkOS, Qdrant and GitHub.

In practice: before piloting Technical Sales Assistant, an IT reviewer requests the current SOC 2 Type II report, audit documentation and data privacy policies from Kimia's trust portal, then checks the audit period is recent. A compliance badge on a website is not evidence. The report is.

Access control sits with your administrators

Inside the platform, governance means your administrators decide who sees what, without the vendor in that decision. Require role-based permissions, enterprise SSO and directory sync, so access follows your identity provider rather than a separate user list the vendor maintains. Kimia ships all three as standard. When someone joins your organisation, changes role or leaves, their Kimia access follows the change in your own directory.

In practice: a chemical supplier gives application engineers formulation-level access while distributors and regional reps see finished product documents only. When a rep leaves, deactivating the account in the supplier's identity provider removes Kimia access with it. There is no separate offboarding list to maintain.

Every answer traces to a source you own

Governance extends to outputs. Generic AI tools hallucinate: they invent chemicals, fabricate product specs and present fiction as fact, so require answers your team can verify rather than answers taken on trust. Kimia grounds every response in your own knowledge base, with source attribution so your team can trace any answer back to the original document or data point. Confidence scoring flags when the system is less certain, so your team knows when to verify.

In practice: a rep quotes open time and viscosity for a hot-melt adhesive grade during a customer call. Source attribution shows the exact TDS revision behind each figure, so the rep verifies the answer before it reaches the customer's engineering team.

What this standard delivers

  • Contained data. Formulations and customer records stay inside your workspace and never train shared models.

  • Evidenced compliance. SOC 2 Type II and GDPR claims backed by reports you can read.

  • Controlled access. Permissions that follow your own identity provider.

  • Traceable answers. Every response linked to the source document behind it.

Data governance is a fixed requirement, not a negotiation. A chemical AI vendor that publishes its training policy, its isolation model and its audit evidence has nothing to hide, and Kimia publishes all three.

FAQ

Does Kimia train its models on your data?

No. Kimia's chemical intelligence is built on public chemical data, and your proprietary product data, formulations and customer information are used solely to improve your own organisation's experience. Learnings never leak to other customers or external systems, and nothing you load into your workspace trains models shared across Kimia customers.

Is Kimia SOC 2 Type II and GDPR compliant?

Yes. Kimia is SOC 2 Type II and GDPR compliant, with enterprise authentication and encryption as standard. Kimia also runs on SOC 2 and GDPR-certified infrastructure partners including AWS, WorkOS, Qdrant and GitHub, and its trust portal holds the compliance reports, audit documentation and data privacy policies needed for a full security review.

What is the difference between SOC 2 Type I and SOC 2 Type II?

SOC 2 Type I assesses whether a vendor's security controls are suitably designed at a single point in time, while SOC 2 Type II tests whether those controls operated effectively over a sustained audit period. Type II is the stronger assurance for a chemical AI purchase, because it shows the vendor ran its controls continuously rather than assembling them for an audit date.

Where is your data stored when you use Kimia?

Your data is stored in a fully isolated workspace, separated from every other Kimia customer, on infrastructure provided by SOC 2 and GDPR-certified partners including AWS, WorkOS, Qdrant and GitHub. Your data, outputs and activity never mix with another customer's, and you can export everything at any time.

Can you delete your data if you cancel?

Yes. You can export your data at any time during the contract, and if you cancel, your data is deleted from Kimia's systems upon request. Confirm both rights in writing with any chemical AI vendor before you load formulations or customer records, because exit terms are hardest to negotiate after the data has moved.

Solutions
Platform
About