KONDWIT Trust Center
Security, privacy, and reliability information for procurement teams, security reviewers, and customers conducting due diligence on KONDWIT.
Certifications
None yet. KONDWIT holds no SOC 2 report and no other security certification. The SOC 2 effort is in its readiness phase: no auditor is engaged and no audit window has opened. See Compliance for the current state and the program timeline.
What we protect
Encryption at rest and in transit
AES-256 at rest on Postgres, Redis, and Key Vault, plus application-layer envelope encryption on PII columns. TLS 1.2+ in transit. KONDWIT operates no object-storage account; Neo4j Aura at-rest encryption is vendor-stated.
Hash-chained audit log
Every security-relevant action recorded on an append-only hash chain, with a daily signed anchor. The anchor is held inside the platform, not externally timestamped; seven-year retention is our policy target, not an enforced mechanism.
Tenant isolation
Per-org JWT scope and row-level org binding, enforced at the data layer by a fail-closed query fence. A CI gate binds that fence to the database schema, so a new table carrying an organization identifier cannot ship without being classified: either inside the fence, or excluded with a recorded reason.
GDPR + CCPA ready
Customer-executed DPA, 72-hour breach notification, right-to-access + right-to-erasure.
Common procurement asks
- Request the encryption posture (under NDA) — there is no SOC 2 report to request yet
- View the DPA template
- See our sub-processor list
- SLO targets + incident history
- Report a vulnerability