Compliance at Kira
We align our program with recognized security and privacy frameworks and support the rights granted under major data-protection laws. This page summarizes our posture specifically for procurement and security teams doing vendor evaluation, the audience that actually needs this page tends to be someone running a formal review before signing off on a new vendor, not a casual visitor browsing features. Full technical detail lives on our Security & Compliance page, this page exists to give you the executive summary version, with enough specificity that you can make a real judgment rather than just seeing a list of framework names and logos.
Frameworks and Certifications
| Framework | Status | Scope |
|---|---|---|
| SOC 2 Type II | In progress | Security, availability, confidentiality |
| ISO/IEC 27001 | Planned | Information security management |
| GDPR | Compliant | EU/EEA personal data |
| CCPA / CPRA | Compliant | California consumer privacy |
What "SOC 2 Type II: In Progress" Actually Means
It's worth being specific here rather than leaving that status line to speak for itself, since vague compliance language is exactly what erodes trust with a technically literate reviewer. A SOC 2 Type I audit evaluates whether an organization's controls are properly designed at a single point in time, essentially, do the right policies and safeguards exist on paper, are they structured sensibly. A Type II audit goes considerably further, assessing whether those controls actually operated effectively over a real observation period, typically several months of evidence gathered and tested by an independent auditor, not a one-time snapshot taken on a good day.
Type II is what most enterprise buyers actually want to see, and for good reason, it demonstrates sustained practice over time, not just a well-written policy document that might not reflect how things actually work day to day. Our program is being built directly toward a Type II audit, not a Type I as an intermediate stop, since we'd rather invest the additional time to get to the report that actually matters to buyers rather than checking a lesser box first. We'll update this status the moment a report is available, along with the actual reporting period covered, since a report's currency matters as much as its existence.
Whose Controls Are Whose
A meaningful part of Kira's compliance posture is inherited directly from running on Amazon Web Services, and it's worth being clear about which controls are genuinely ours versus theirs, since a complete compliance picture depends on both layers working together correctly, not just one or the other in isolation.
AWS's own infrastructure, physical data center security, environmental controls, employee vetting and background checks at the infrastructure layer, redundant power and cooling systems, is covered under AWS's own SOC 2 and related attestations, which we can point you to directly as part of any vendor review your team is conducting. This is genuinely significant infrastructure security that neither we nor most companies our size could realistically replicate independently, and it's worth citing specifically rather than implying it's something Kira built from scratch ourselves.
What's specifically ours, built on top of that foundation, is everything at the application layer: our encryption implementation, our access controls governing who at Kira can actually see customer data and under what circumstances, our incident response process and the specific playbooks we follow when something goes wrong, and our own product-specific security decisions, like requiring approval before high-stakes agent actions. A thorough vendor review genuinely should evaluate both layers together, since a secure application built on insecure infrastructure isn't actually secure in any meaningful sense. Ask us for both pieces if you're doing a formal review.
What You Still Need to Do on Your End
Even a fully compliant vendor's controls only protect you as fully as you configure your own account properly, and it would be dishonest to imply otherwise just to make our own compliance posture sound more complete than it actually is. This is sometimes formally referred to as Complementary User Entity Controls in a formal audit context, essentially, the specific things that remain your organization's responsibility regardless of how strong our own program is, and regardless of what certifications we eventually hold.
Specifically, this includes managing who on your team has access to your Kira workspace and at what permission level, promptly removing access when someone leaves your organization rather than letting a departed employee's credentials linger active for weeks, and configuring integration permissions thoughtfully rather than granting a connected tool broader access than it actually needs to function. Our compliance program handles the platform side of this relationship comprehensively, encryption, infrastructure security, our own internal access controls, but your own account configuration handles the other half, and no vendor's certification, however rigorous, substitutes for your own team's diligence here.
Data Residency
Kira runs on AWS. Depending on your plan and region, US or EU data residency options may be available. Contact us to discuss requirements for your organization. For full regional detail, including what data residency does and doesn't cover for AI processing specifically, an important nuance worth understanding before relying on residency alone for AI-touching workflows, see our Regional Compliance page.
Sub-Processors
We rely on a small set of vetted providers, each bound by data-protection terms consistent with our obligations to you. Keeping this list genuinely short is a deliberate choice on our part, every additional processor is another party worth evaluating carefully, so we only add one when it's genuinely necessary to deliver the service rather than for convenience alone. The current, complete list is maintained on our Security & Compliance page.
How We Handle Formal Vendor Reviews
If your organization is running a formal vendor security assessment as part of procurement, whether that's a standardized questionnaire, a SIG Lite, or your own internally built assessment template, we'd genuinely rather work through it with you directly than ask you to reverse-engineer complete answers from our public pages alone. Public compliance pages, by design, summarize rather than exhaustively document every control, and a real vendor review often has specific questions that don't map cleanly onto a marketing page's structure. Reach out to support@kiraai.ai or support@kiraai.ai with your questionnaire or assessment template, and we'll work through it properly rather than pointing you back to this page and calling it complete.
Request Documentation
Eligible customers can request our security overview, attestations, sub-processor list, and a Data Processing Addendum (DPA) by contacting support@kiraai.ai or support@kiraai.ai.
References
Frequently asked questions
Quick answers to common questions.
Our SOC 2 Type II program is in progress. Eligible customers can request the latest status and, once available, the report itself under NDA.
Type I assesses whether controls are properly designed at a single point in time. Type II assesses whether those controls actually operated effectively over a real period, which is specifically what we're working toward, since it's the standard most enterprise buyers actually rely on.
Both matter, and they're covered separately. AWS's own attestations cover the physical and infrastructure layer; our own controls cover the application, access, and incident response layer built on top of it. We can point you to both as part of a vendor review.
Yes. We make a Data Processing Addendum available to business customers. Request it from support@kiraai.ai.
Yes. We honor the rights granted under the GDPR and CCPA/CPRA. See our Privacy Policy.
Managing your own team's access, removing access promptly when someone leaves, and configuring integration permissions thoughtfully. Our controls handle the platform; your account configuration handles the rest, and no certification we hold changes that division of responsibility.
Yes. Send it to support@kiraai.ai or support@kiraai.ai and we'll work through it properly, since a formal review often needs more specificity than a public summary page is designed to provide.