SOC 2 Type II
Security, Availability, Confidentiality
In progressType II audit in progress · readiness report under NDA
Kimo connects to your most sensitive systems: revenue, customers, and for some teams, mission data. Here is exactly how we protect it, from the first sync to the last dashboard.
Independent auditors check our controls every year. Reports are available under NDA from the document request form.
Security, Availability, Confidentiality
In progressType II audit in progress · readiness report under NDA
ISMS for the Kimo platform
In progressControls aligned with ISO/IEC 27001:2022 · certification planned
Processor & controller obligations
ReadyDPA with SCCs · EU data residency
French health data hosting
In progressCertification audit scheduled Q1 2027
Sovereign deployments
ReadyRuns on qualified providers · on-prem & air-gapped
Demo site: certifications and audit dates shown here are illustrative.
Same product, four ways to run it. Pick a tenancy mode to see where the trust boundary moves.
Every workspace, backup and cache is encrypted with a dedicated data key, wrapped by a per-tenant master key.
TLS 1.3 everywhere, HSTS preloaded, and mutual TLS between internal services. Connectors support SSH tunnels and PrivateLink.
Enterprise workspaces can hold the master key in their own KMS or HSM. Revoke it, and Kimo can no longer read a byte.
Source credentials live in a dedicated vault, are never logged, and are only decrypted inside the sync worker that needs them.
Pinned per workspace at creation.
Defaults, and what happens when you leave.
| Data | Default | Configurable | Purged after offboarding |
|---|---|---|---|
| Synced source data | While connected | Yes | 30 days |
| Query result cache | 24 hours | Yes | Immediate |
| Audit log | 13 months | Yes | Exported, then 30 days |
| Encrypted backups | 35 days, rolling | Fixed | 35 days |
| Ask Kimo questions | 90 days | Yes | Immediate |
| Application logs (scrubbed) | 30 days | Fixed | 30 days |
Identity comes from your IdP. Permissions are enforced in the query engine, not the UI, so an API call sees exactly what a dashboard sees.
Okta, Entra ID, Google Workspace or any SAML/OIDC provider. Enforce SSO and disable passwords per workspace.
Users and groups sync from your IdP. Offboard someone there and their Kimo access is gone within a minute.
Roles for what people can do, attributes for what they can see: region = "EMEA", clearance ≥ "restricted".
Every login, query, export and permission change is logged, immutable, and streamable to your SIEM.
Multi-zone, with automatic failover and a 99.9% SLA on Business plans (99.95% on Enterprise). Every incident gets a public post-mortem.
We keep this list small and tell you 30 days before it changes.
| Subprocessor | Purpose | Data | Location | Region |
|---|---|---|---|---|
| OVHcloud | Primary hosting (EU region) | Customer data | Gravelines & Strasbourg, FR | EU |
| Scaleway | Backups & disaster recovery | Encrypted backups | Paris, FR | EU |
| Google Cloud | Hosting (US region only) | Customer data (US tenants) | Iowa, US | US |
| Cloudflare | CDN, WAF and DDoS protection | Request metadata | Global edge, EU logs | EU + US |
| Mistral AI | LLM inference for Ask Kimo (opt-in) | Questions + schema, no rows | Paris, FR | EU |
| Stripe | Billing and payments | Billing contacts | Dublin, IE | EU + US |
| Sentry | Error monitoring (scrubbed) | Stack traces, no customer rows | Frankfurt, DE | EU |
| Intercom | In-app support chat | Support conversations | Dublin, IE | EU |
Good-faith research is welcome and protected by our safe-harbor policy. Please do not access other customers’ data or degrade the service.
Contact: mailto:security@getkimo.exampleExpires: 2027-10-01T00:00:00ZEncryption: https://getkimo.example/pgp.ascPreferred-Languages: en, frPolicy: https://getkimo.example/security#disclosureAcknowledgments: https://getkimo.example/security#hall-of-fame
4F2A 9C1D 7B3E 08A6 5D91 E2C4 3B7F 6A10 9E58 D3C2Fictional researchers, real gratitude.
Need a filled-in questionnaire? Request the CAIQ from the documents form.
Synced data is stored in your isolated workspace so dashboards are fast. You choose which tables sync and can switch any source to live query mode, where only aggregated results are cached.
Kimo Defense Intelligence runs fully inside your enclave, with signed offline updates and zero phone-home.
Explore Kimo Defense
SOC 2 readiness summary, ISO 27001 SoA, pentest summary, DPA and a pre-filled questionnaire.