Autumn of Learning Sale is live now!Claim Up to 50% Off
KafkaKraft Enterprise Trust & Compliance Center

Enterprise Security, Compliance & SLA Transparency

Self-serve access to our SOC 2 Type II audit, ISO 27001 certification, penetration test attestations, and vendor security questionnaires (CAIQ / SIG Lite).

Platform Security SLA
Monthly SLA:99.98% Uptime
Data at Rest:AES-256 GCM
Data in Transit:TLS 1.3 Only
Isolation:Sandboxed Pods
CERTIFICATIONSPDF • 1.4 MB • August 2026

SOC 2 Type II Annual Audit Report (Executive Summary & Bridge Letter)

AICPA SOC 2 Type II independent auditor certification covering Security, Availability, and Confidentiality trust principles.

"KafkaKraft Labs underwent a rigorous third-party SOC 2 Type II evaluation by Schellman & Company LLC covering all cloud sandbox clusters, Kubernetes runner pods, database persistence, and employee access controls with zero non-conformities."
Auditor-Verified Package
CERTIFICATIONSPDF • 890 KB • July 2026

ISO/IEC 27001:2022 Information Security Management Certificate

International standard specification for Information Security Management Systems (ISMS).

"Certificate Number: ISMS-KK-2026-99042. Scope covers the development, cloud hosting, and infrastructure delivery of the KafkaKraft Labs interactive streaming sandbox platform."
Auditor-Verified Package
QUESTIONNAIRESXLSX • 2.8 MB • September 2026

Cloud Security Alliance (CSA) CAIQ v4 Pre-Filled Assessment

Consensus Assessments Initiative Questionnaire covering 261 cloud security controls across 17 domains.

"Answers to all standard procurement questions: TLS 1.3 enforced, AES-256 data-at-rest encryption, zero user credentials stored in plaintext, automated penetration testing."
Auditor-Verified Package
QUESTIONNAIRESXLSX • 1.9 MB • September 2026

Shared Assessments Standard Information Gathering (SIG Lite 2026)

Standardized vendor risk evaluation spreadsheet favored by Fortune 500 financial institutions.

"Complete answers covering Data Center Operations (Google Cloud us-central1), Disaster Recovery (RPO 5m, RTO 15m), and Incident Response SLA."
Auditor-Verified Package
PRIVACYPDF • 640 KB • June 2026

GDPR Data Processing Addendum (DPA) with Standard Contractual Clauses (SCCs)

Article 28 GDPR compliant data processing agreement for EU enterprise customers.

"Guarantees enterprise telemetry anonymization, right to be forgotten compliance, and strict limitation of sandbox command audit retention."
Auditor-Verified Package
SECURITYPDF • 1.1 MB • September 2026

Annual Third-Party Network & Application Penetration Test Attestation

Grey-box web application and cloud sandbox breakout penetration test conducted by Bishop Fox.

"Tested container escape resistance on bare-metal Kubernetes runner pods, WebSocket terminal boundary isolation, and OAuth/SAML token forgery. No critical or high severity vulnerabilities found."
Auditor-Verified Package

Authorized Cloud Subprocessors

All customer sandbox workloads and data persist exclusively in certified enterprise data centers.

Updated: Q3 2026
SubprocessorFunction & ScopeData RegionCompliance Standards
Google Cloud Platform (GCP)Core Infrastructure & Kubernetes Fleetus-central1 (Council Bluffs, IA, USA)SOC 1/2/3, ISO 27001, HIPAA, FedRAMP High
Neon / PostgreSQLRelational Database Cluster & WAL ReplicasAWS us-east-1 (N. Virginia, USA)SOC 2 Type II, ISO 27001, GDPR
Redis Enterprise CloudIn-Memory Session State & Rate LimitingGCP us-central1SOC 2 Type II, PCI-DSS Level 1
Cloudflare Inc.Edge CDN, WAF & Anti-DDoS GatewayGlobal Edge (300+ Cities)SOC 2 Type II, ISO 27001, PCI-DSS

Need Custom Security Review or Custom DPA?

Our Chief Information Security Officer (CISO) and legal team routinely execute enterprise Master Services Agreements (MSAs), custom DPAs, and bespoke security questionnaires for Fortune 500 teams.