Back to Kavryn
Trust
Kavryn helps cloud-native teams get audit-ready for SOC 2. We hold ourselves to the same bar — and we publish where we are honestly. This page will be the canonical source of our security posture, certifications, and subprocessors. It is intentionally short today because it only contains what is verifiably true today.
Our SOC 2 Type 1 — in progress
We are mid-readiness for our own SOC 2 Type 1 audit. We will publish the report and the auditor's name here once issued. We will not list a logo we have not earned.
What we already do
- Read-only AWS access via scoped IAM roles. We do not store your AWS credentials and we cannot modify your account.
- Customer data and audit evidence are encrypted in transit and at rest.
- Access to production systems is limited to authorized personnel and protected by multi-factor authentication.
- Customer data and audit evidence are backed up regularly.
Reporting a vulnerability
If you believe you have found a security issue, please email security@kavryn.io. We acknowledge within one business day.