Last updated: March 2026

Trust Center

Security, compliance, and data protection at Kolva. Everything you need to evaluate our platform for your organization.

Security Overview

Enterprise-grade security at every layer

Kolva is built with security from the ground up. Multiple layers of defense protect your data across infrastructure, application, and AI processing.

Encryption

AES-256 encryption at rest. TLS 1.3 for all data in transit. End-to-end encryption for API keys.

Access Control

Role-based access control (RBAC), row-level security at database level, API key hashing with SHA-256.

Infrastructure

Supabase on AWS (eu-central-1, Frankfurt). Vercel Edge CDN. SOC 2 compliant hosting across the stack.

AI Security

Customer data is never used for model training. AI processing is ephemeral -- no data retained by providers.

Monitoring

Real-time security alerting, anomaly detection. 24/7 automated infrastructure monitoring.

Comprehensive Audit Trail

Immutable audit logs tracking all user actions — logins, role changes, API key management, data exports, integrations. 36-month retention, zero deletions.

Development

Secure SDLC with mandatory code review. Automated dependency scanning. Staging environment testing.

View full security details

Compliance Status

Certifications and regulatory compliance

SOC 2 Type II

In Progress

In Progress — Audit logging enabled, all user actions tracked, immutable logs with 36-month retention. Service Organization Control audit covering security, availability, and confidentiality. Expected Q2 2026.

GDPR

Compliant

Full compliance with the EU General Data Protection Regulation. DPA available for all customers.

CCPA

Compliant

California Consumer Privacy Act compliance. Data access, deletion, and opt-out rights fully supported.

ISO 27001

Planned

Information security management system certification. On the roadmap for 2027.

HIPAA

Not applicable

Kolva does not process protected health information (PHI). Not in scope.

Download Data Processing Agreement

Data Handling

How we handle your data

Data Residency

Primary region: EU (AWS eu-central-1, Frankfurt). US region available on request for Enterprise plans.

Data Encryption

AES-256 at rest for all stored data. TLS 1.3 in transit for every API call, webhook, and agent sync.

Data Retention

Configurable per company. Default: 36 months. Data deletion on request within 30 days. Full GDPR export.

Backups

Daily automated backups with point-in-time recovery. 30-day backup retention. Encrypted in transit and at rest.

On-Premise Option

ERP agents run on your corporate network. Data stays local until synced over HTTPS. No inbound ports required.

On-Premise Agent Data Flow

Your network
ERP System
Sage X3 / SAP
SELECT / GET only
Your network
Kolva Agent
Node.js service
HTTPS POST
EU (Frankfurt)
Kolva Cloud
PostgreSQL / AES-256

No write path exists from Kolva to your ERP. The data flow is strictly one-way. No inbound ports required.

Sub-processors

Third-party service providers

ProviderPurposeLocationCompliance
SupabaseDatabase & AuthenticationAWS EU (Frankfurt)SOC 2
VercelHosting & CDNGlobal EdgeSOC 2
StripePayment ProcessingUS / EUPCI DSS Level 1
ResendTransactional EmailUSSOC 2
AnthropicAI Processing (Claude)USSOC 2
OpenAISpeech Processing (Whisper)USSOC 2
InngestTask OrchestrationUSSOC 2
UpstashRate Limiting & CachingGlobalSOC 2

Last updated: March 2026. We notify customers 30 days before adding new sub-processors.

Documents & Resources

Legal and security documentation

Incident Response

Our commitment when things go wrong

< 1 hour

Response time for critical incidents

< 4 hours

Customer notification for data incidents

5 days

Post-mortem published (business days)

We maintain a public status page with real-time uptime monitoring and incident history.

View system status

Questions about security or compliance?

Our team is ready to help with security assessments, compliance questionnaires, or any data protection inquiries. We also welcome responsible vulnerability disclosures.

Ready to get started?

21-day free trial. No credit card required.