Last updated: July 26, 2026

Trust Center

Security, compliance, and data protection at Kolva. Everything you need to evaluate our platform for your organization.

Security and control

Enterprise intelligence without losing control

Your ERP data remains governed by your organization. Kolva applies controlled access, human validation, and revocable permissions across the intelligence layer.

Read-only ERP access by default

ERP agents use read-only source access unless a separately scoped action is explicitly enabled.

Encryption in transit and at rest

Transport and storage protections cover data moving through Kolva and data persisted by the platform.

Scoped permissions

User, role, company, and data scopes determine which context and actions are available.

Sanitized discovery data

Discovery workflows minimize and sanitize technical metadata before support analysis.

Traceable support actions

Support interventions follow a controlled workflow with actor, scope, and timing context.

Human validation for sensitive actions

Permission-gated actions inside Kolva require explicit authorization and human validation. The standard ERP synchronization path remains outbound and read-only.

Customer-controlled revocation

Customers retain control over connector, user, token, and assistant access revocation.

View full security details

Compliance Status

Certifications and regulatory compliance

SOC 2 Type I

In Progress

Type I in progress — Type II to follow. Audit logging enabled, all user actions tracked, immutable logs with 36-month retention. Service Organization Control audit covering security, availability, and confidentiality.

GDPR

Compliant

Full compliance with the EU General Data Protection Regulation. DPA available for all customers.

CCPA

Compliant

California Consumer Privacy Act compliance. Data access, deletion, and opt-out rights fully supported.

ISO 27001

Planned

Information security management system certification. On the roadmap for 2027.

HIPAA

Not applicable

Kolva does not process protected health information (PHI). Not in scope.

Download Data Processing Agreement

Data Handling

How we handle your data

Data Residency

Primary region: EU (AWS eu-west-1, Ireland). Any alternate residency requirement is reviewed contractually before rollout.

Data Encryption

AES-256 at rest for all stored data. TLS 1.3 in transit for every API call, webhook, and agent sync.

Data Retention

Configurable per company. Default: 36 months. Data deletion on request within 30 days. Full GDPR export.

Backups

Daily automated backups with point-in-time recovery. 30-day backup retention. Encrypted in transit and at rest.

On-Premise Option

ERP agents run on your corporate network. Data stays local until synced over HTTPS. No inbound ports required.

On-Premise Agent Data Flow

Your network
ERP System
Sage X3 / SAP
SELECT / GET only
Your network
Kolva Agent
Node.js service
HTTPS POST
EU (Ireland)
Kolva Cloud
PostgreSQL / AES-256

The standard ERP synchronization path is outbound-only and requires no inbound ports. Separately enabled sensitive actions use explicit, permission-gated workflows outside this default read path.

Sub-processors

Third-party service providers

Kolva sub-processors, purposes, locations, and compliance
ProviderPurposeLocationCompliance
SupabaseDatabase & AuthenticationAWS EU (Ireland)SOC 2
VercelHosting & CDNGlobal EdgeSOC 2
StripePayment ProcessingUS / EUPCI DSS Level 1
ResendTransactional EmailUSSOC 2
AnthropicAI Processing (Claude)USSOC 2
OpenAISpeech Processing (Whisper)USSOC 2
InngestTask OrchestrationUSSOC 2
UpstashRate Limiting & CachingGlobalSOC 2

Last updated: July 26, 2026. We notify customers 30 days before adding new sub-processors.

Documents & Resources

Legal and security documentation

Incident Response

Our commitment when things go wrong

< 1 hour

Response time for critical incidents

< 4 hours

Customer notification for data incidents

5 days

Post-mortem published (business days)

We maintain a public status page with real-time uptime monitoring and incident history.

View system status

Questions about security or compliance?

Our team is ready to help with security assessments, compliance questionnaires, or any data protection inquiries. We also welcome responsible vulnerability disclosures.

Ready to get started?

21-day free trial. No credit card required.