Security Posture

Security & Compliance

How Kontaim meets enterprise security and data-protection expectations: SOC 2 readiness, GDPR, and the operational controls that back the contract.

Last updated: September 6, 2026

30

Controls assessed

20

Met today

10

In progress / planned

Standards & Audits

SOC 2 Type I report

In progress: pre-audit readiness phase. Target: Q4 2026.

In progress

SOC 2 Type II report

Planned, following Type I + 6 month observation window.

Planned

ISO 27001 alignment

Controls mapped against ISO 27001:2022 Annex A; certification not yet pursued.

In progress

GDPR (Article 28 processor obligations)

Standard DPA with SCCs available; subprocessor list published.

In place

CCPA / CPRA

Subject-request handling and "do-not-sell" obligations honored; service-provider role disclosed in privacy policy.

In place

Data Protection

Encryption in transit

TLS 1.2+ on all external endpoints; HSTS enforced.

In place

Encryption at rest

AES-256 on managed Postgres (Supabase); managed key rotation.

In place

Backup encryption

Encrypted daily backups with point-in-time recovery, managed by our database provider.

In place

Key management

Application-layer secrets in Vercel managed env; database keys managed by cloud provider HSM.

In place

Identity & Access

Least-privilege access

Production data is reachable only through row-level security policies and role-checked server functions; infrastructure access is limited to the founding team.

In place

Multi-factor authentication

Enabled on the cloud consoles that hold production access (hosting, database, source control).

In place

SSO for customers

SAML 2.0 / OIDC planned for enterprise plans; email and password sign-in today.

Planned

Row-level authorization

Postgres RLS policies on every table containing Customer data.

In place

Audit logging

Administrative actions run through role-checked server functions; application events are logged in the database. Centralized tamper-resistant log retention is planned with SOC 2 readiness.

In progress

Incident Response

Breach-notification SLA

Customer notification within 72 hours of confirmed Personal Data Breach.

In place

Documented IR runbook

Internal incident-response playbook; founder-led response.

In place

Tabletop exercises

Planned as part of SOC 2 readiness.

Planned

Vulnerability Management

Dependency monitoring

Automated dependency vulnerability alerts on the source repository.

In place

Vulnerability scanning

Application-level SAST/DAST is planned alongside SOC 2 readiness; hosting and database infrastructure are managed services scanned by the providers.

Planned

Penetration testing

Annual third-party pentest planned alongside SOC 2 Type I.

In progress

Responsible-disclosure channel

Security reports accepted at security@kontaim.com; acknowledgment within 1 business day.

In place

Data Subject Rights

Access / portability

Customer data exportable via the dashboard; programmatic export available on request.

In place

Rectification / deletion

Self-serve deletion within the product; bulk requests processed within 72 hours.

In place

Subprocessor change notification

Material additions notified at least 30 days in advance.

In place

Resilience

Recovery point objective (RPO)

≤ 24 hours (daily backups with point-in-time recovery on managed Postgres).

In place

Recovery time objective (RTO)

Target ≤ 4 hours for critical production restoration; not yet rehearsed.

In progress

Disaster-recovery testing

DR rehearsal planned as part of SOC 2 readiness.

Planned

AI & Customer Content

No model training on Customer Content

Requests go through the providers' business APIs (Google, OpenAI, Anthropic), whose published terms exclude API inputs from model training. No separate enterprise agreements are in place.

In place

AI output review

Customer is responsible for reviewing AI-generated content before publishing to Participants.

In place

Content moderation

AI screening pass on publish; flagged content is held for Customer review.

In place

Technical Specifications

Infrastructure

  • Database: Supabase (Postgres), Canada (Montreal) primary
  • Hosting: Vercel Edge Network
  • CDN: Vercel CDN (no PII cached)
  • Payments: Stripe (PCI-DSS Level 1)

Encryption Standards

  • In Transit: TLS 1.2+ (1.3 preferred)
  • At Rest: AES-256
  • Hashing: bcrypt for passwords; SCRAM-SHA-256 in transit
  • Secrets: Managed env (Vercel) + cloud provider HSM

For SIG / CAIQ responses, our SOC 2 report (when available), or to start a security review, contact support@kontaim.com.

Security & Compliance | Kontaim