Trust & compliance
Built so your security and legal teams can say yes.
Kavanah is designed for teams that work with regulated industries, sensitive client data, and procurement processes that ask hard questions. Here's where we stand.
Encryption everywhere
TLS 1.2+ in transit, AES-256 at rest. Per-workspace key separation for sensitive fields.
Immutable audit logs
Security-relevant read, write, and admin actions recorded. Database-enforced immutability. Configurable retention up to 7+ years, with legal holds suspending deletion.
GDPR / DSAR ready
Export or erase a subject's data on request. Consent records and Data Processing Addenda built in.
Legal hold & eDiscovery
Freeze deletion of specific projects, users, or workspaces under litigation. Search and export across messages, tasks, and audit logs.
Documents & resources
The full evaluation library — product, technical, security, legal, commercial, and delivery documentation. Self-serve, no request required. Artifacts released under NDA are listed further down.
Overview & positioning
Executive Product Overview
Business value, target use cases, differentiators, and the outcomes customers should expect.
Company One-Pager
The whole company on a single page — problem, product, market, and pricing. Downloadable as a PDF.
Capabilities Matrix
Functional coverage by area, in the table format RFP responses ask for.
Product & technical specifications
Product Data Sheet
Features, editions, limits, integrations, and platform support — the standard enterprise-sales datasheet.
Technical Data Sheet
Deployment model, system requirements, API surface, performance envelope, security controls, and integration specifications.
Architecture Overview & Diagram
System architecture — components, data flows, integration paths, and trust boundaries — with a labelled diagram.
Functional Requirements Document
Numbered, testable statements of what the application does — the requirement IDs an enterprise implementation traces against.
Functional Specification Document
How the product behaves — workflows, screen-by-screen user behavior, business logic, and rules.
Software Requirements Specification
Comprehensive functional and non-functional requirements in IEEE-830 shape, for regulated and custom-development buyers.
Software Design Specification
Technical design for engineering reviewers — module decomposition, data model, request lifecycle, and design decisions.
API Documentation
The full REST API reference (Developer API tab) and the machine-readable OpenAPI 3.1 specification at /openapi.yaml.
Security, privacy & compliance
Security & Compliance Overview
The security whitepaper — encryption, identity, tenant isolation, monitoring, personnel, vulnerability management, and the compliance program.
Disaster Recovery & Business Continuity Plan
Recovery objectives (RPO/RTO), backup and failover design, incident severities, and the continuity plan for the business itself.
AI Transparency
What customer data reaches AI providers, the no-training posture, and how agent actions are governed and logged.
Sub-processors
Every vendor that processes customer data, what it does, and where it operates.
Legal & contractual
Commercial
Delivery & support
Buyer response packs
Certifications & artifacts
Some artifacts are shared under NDA. Submit a request and our security team will respond within two business days.
SOC 2 Type II
In observation periodIndependent attestation of our security, availability, and confidentiality controls. The full report is available under NDA on request.
- Annual Type II audit by a licensed CPA firm
- Covers access control, change management, incident response, monitoring
- Bridge letter and gap analysis available for active engagements
ISO/IEC 27001
Targeting Q4 2027International standard for an Information Security Management System. We are aligning our control framework now and pursuing formal certification.
- Statement of Applicability mapped to Annex A controls
- Risk assessment cadence aligned to SOC 2 program
- Pre-certification readiness review available to enterprise customers
HIPAA BAA
Available on EnterpriseBusiness Associate Agreement for healthcare customers handling Protected Health Information (PHI). Covers safeguards, breach notification, and subcontractor handling.
- Signed BAA before any PHI is processed
- Sensitive fields can be classified and encrypted at rest (per-workspace keys) via Data Governance
- Audit-log retention is configurable to meet HIPAA's 6-year requirement, and legal holds suspend deletion
Penetration test summary
Refreshed annuallyExecutive summary of our most recent third-party penetration test, including remediation status. Detailed findings shared under NDA.
- Annual external network and application penetration test
- Critical and high findings tracked to closure within SLA
- Detailed report shared with security teams under NDA
For data privacy questions (GDPR DSAR, Data Processing Addendum), workspace owners can initiate requests directly from Settings → Data Governance. For all other inquiries, email security@kavanah.ai.