SOC 2 Type II
Audited annually by a Big Four firm. Report available on request under NDA.
Security
Authentication is the most consequential dependency in your stack. We're not asking you to take that on faith — here's what we actually do.
Certifications
Audited annually by a Big Four firm. Report available on request under NDA.
Certified by an accredited body. Surveillance audits every 12 months.
Standard Contractual Clauses and EU data residency by default for EU customers.
BAA available on Team and Enterprise plans for covered entities.
Posture
Customer signing keys are encrypted at rest with envelope encryption. We cannot decrypt them; the KMS holds the unwrapping keys behind hardware HSMs.
Network isolation, WAF, per-endpoint rate limiting, anomaly detection, and audited admin paths. Any one layer failing does not give an attacker your data.
All inter-service auth uses short-lived workload identities. No static API tokens stored in environment variables anywhere in our infrastructure.
Public bounty program plus annual third-party penetration tests. Findings are remediated under tracked SLAs.
Disclosure
We run a public security disclosure program. Send a detailed report to security@klauthed.com — PGP keys and severity SLAs are documented at /security/disclosure.