Security Posture

Security & Compliance

How Kontaim meets enterprise security and data-protection expectations — SOC 2 readiness, GDPR, and the operational controls that back the contract.

Last updated: May 14, 2026

30

Controls assessed

24

Met today

6

In progress / planned

Standards & Audits

SOC 2 Type I report

In progress — pre-audit readiness phase. Target: Q4 2026.

In progress

SOC 2 Type II report

Planned — following Type I + 6 month observation window.

Planned

ISO 27001 alignment

Controls mapped against ISO 27001:2022 Annex A; certification not yet pursued.

In progress

GDPR (Article 28 processor obligations)

Standard DPA with SCCs available; subprocessor list published.

In place

CCPA / CPRA

Subject-request handling and "do-not-sell" obligations honored; service-provider role disclosed in privacy policy.

In place

Data Protection

Encryption in transit

TLS 1.2+ on all external endpoints; HSTS enforced.

In place

Encryption at rest

AES-256 on managed Postgres (Supabase); managed key rotation.

In place

Backup encryption

Encrypted point-in-time backups with rolling 35-day retention; secure deletion.

In place

Key management

Application-layer secrets in Vercel managed env; database keys managed by cloud provider HSM.

In place

Identity & Access

Least-privilege access

Production access scoped by role; permissions reviewed quarterly.

In place

Multi-factor authentication

Required for all employee accounts to platform infrastructure.

In place

SSO for customers

SAML 2.0 / OIDC available on enterprise plans.

In place

Row-level authorization

Postgres RLS policies on every table containing Customer data.

In place

Audit logging

Centralized logs for administrative and access events with tamper-resistant retention.

In place

Incident Response

Breach-notification SLA

Customer notification within 72 hours of confirmed Personal Data Breach.

In place

Documented IR runbook

Internal incident-response playbook with on-call rotation.

In place

Tabletop exercises

Conducted semi-annually as part of SOC 2 readiness.

In progress

Vulnerability Management

Dependency monitoring

Automated dependency scanning on every commit and on a daily cadence.

In place

Vulnerability scanning

Continuous SAST/DAST on the application; container/runtime scanning on infrastructure.

In place

Penetration testing

Annual third-party pentest planned alongside SOC 2 Type I.

In progress

Responsible-disclosure channel

Security reports accepted at security@kontaim.com; acknowledgment within 1 business day.

In place

Data Subject Rights

Access / portability

Customer data exportable via the dashboard; programmatic export available on request.

In place

Rectification / deletion

Self-serve deletion within the product; bulk requests processed within 72 hours.

In place

Subprocessor change notification

Material additions notified at least 30 days in advance.

In place

Resilience

Recovery point objective (RPO)

≤ 24 hours (point-in-time recovery on managed Postgres).

In place

Recovery time objective (RTO)

≤ 4 hours for critical production restoration.

In place

Disaster-recovery testing

Annual DR rehearsal as part of SOC 2 readiness.

In progress

AI & Customer Content

No model training on Customer Content

Enterprise AI provider agreements forbid retention of Customer inputs for model training.

In place

AI output review

Customer is responsible for reviewing AI-generated content before publishing to Participants.

In place

Content moderation

AI screening pass on publish; flagged content is held for Customer review.

In place

Technical Specifications

Infrastructure

  • Database: Supabase (Postgres) — Canada (Montreal) primary
  • Hosting: Vercel Edge Network
  • CDN: Vercel CDN (no PII cached)
  • Payments: Stripe (PCI-DSS Level 1)

Encryption Standards

  • In Transit: TLS 1.2+ (1.3 preferred)
  • At Rest: AES-256
  • Hashing: bcrypt for passwords; SCRAM-SHA-256 in transit
  • Secrets: Managed env (Vercel) + cloud provider HSM

For SIG / CAIQ responses, our SOC 2 report (when available), or to start a security review, contact support@kontaim.com.