Security & Compliance
How Kontaim meets enterprise security and data-protection expectations: SOC 2 readiness, GDPR, and the operational controls that back the contract.
Last updated: September 6, 2026
30
Controls assessed
20
Met today
10
In progress / planned
Standards & Audits
SOC 2 Type I report
In progress: pre-audit readiness phase. Target: Q4 2026.
SOC 2 Type II report
Planned, following Type I + 6 month observation window.
ISO 27001 alignment
Controls mapped against ISO 27001:2022 Annex A; certification not yet pursued.
GDPR (Article 28 processor obligations)
Standard DPA with SCCs available; subprocessor list published.
CCPA / CPRA
Subject-request handling and "do-not-sell" obligations honored; service-provider role disclosed in privacy policy.
Data Protection
Encryption in transit
TLS 1.2+ on all external endpoints; HSTS enforced.
Encryption at rest
AES-256 on managed Postgres (Supabase); managed key rotation.
Backup encryption
Encrypted daily backups with point-in-time recovery, managed by our database provider.
Key management
Application-layer secrets in Vercel managed env; database keys managed by cloud provider HSM.
Identity & Access
Least-privilege access
Production data is reachable only through row-level security policies and role-checked server functions; infrastructure access is limited to the founding team.
Multi-factor authentication
Enabled on the cloud consoles that hold production access (hosting, database, source control).
SSO for customers
SAML 2.0 / OIDC planned for enterprise plans; email and password sign-in today.
Row-level authorization
Postgres RLS policies on every table containing Customer data.
Audit logging
Administrative actions run through role-checked server functions; application events are logged in the database. Centralized tamper-resistant log retention is planned with SOC 2 readiness.
Incident Response
Breach-notification SLA
Customer notification within 72 hours of confirmed Personal Data Breach.
Documented IR runbook
Internal incident-response playbook; founder-led response.
Tabletop exercises
Planned as part of SOC 2 readiness.
Vulnerability Management
Dependency monitoring
Automated dependency vulnerability alerts on the source repository.
Vulnerability scanning
Application-level SAST/DAST is planned alongside SOC 2 readiness; hosting and database infrastructure are managed services scanned by the providers.
Penetration testing
Annual third-party pentest planned alongside SOC 2 Type I.
Responsible-disclosure channel
Security reports accepted at security@kontaim.com; acknowledgment within 1 business day.
Data Subject Rights
Access / portability
Customer data exportable via the dashboard; programmatic export available on request.
Rectification / deletion
Self-serve deletion within the product; bulk requests processed within 72 hours.
Subprocessor change notification
Material additions notified at least 30 days in advance.
Resilience
Recovery point objective (RPO)
≤ 24 hours (daily backups with point-in-time recovery on managed Postgres).
Recovery time objective (RTO)
Target ≤ 4 hours for critical production restoration; not yet rehearsed.
Disaster-recovery testing
DR rehearsal planned as part of SOC 2 readiness.
AI & Customer Content
No model training on Customer Content
Requests go through the providers' business APIs (Google, OpenAI, Anthropic), whose published terms exclude API inputs from model training. No separate enterprise agreements are in place.
AI output review
Customer is responsible for reviewing AI-generated content before publishing to Participants.
Content moderation
AI screening pass on publish; flagged content is held for Customer review.
Technical Specifications
Infrastructure
- • Database: Supabase (Postgres), Canada (Montreal) primary
- • Hosting: Vercel Edge Network
- • CDN: Vercel CDN (no PII cached)
- • Payments: Stripe (PCI-DSS Level 1)
Encryption Standards
- • In Transit: TLS 1.2+ (1.3 preferred)
- • At Rest: AES-256
- • Hashing: bcrypt for passwords; SCRAM-SHA-256 in transit
- • Secrets: Managed env (Vercel) + cloud provider HSM
For SIG / CAIQ responses, our SOC 2 report (when available), or to start a security review, contact support@kontaim.com.