Compliance
We adhere to the highest standards of security and privacy

ISO 27001
ISO/IEC 27001:2022 information security, cybersecurity and privacy protection

ISO 27701
ISO/IEC 27701:2019 privacy information management — extension to information security management

PCI
PCI DSS v4.0.1 - Service Provider payment card industry data security standard — protection of cardholder data and secure payment processing

SOC 2 Type 1
SOC 2 Type I trust services compliance — evaluates design of security and controls at a point in time

SOC 2 Type 2
SOC 2 Type II demonstrates that an organization’s security, availability, and confidentiality controls are not only properly designed but also consistently operating effectively over a defined period of time.
HIPAA
HIPAA (the Health Insurance Portability and Accountability Act) is a U.S. regulation that establishes national standards to protect the privacy, security, and integrity of individuals’ protected health information (PHI).
Monitoring
Display the security controls you’re continuously monitoring within Secureframe.
Resources
Get our latest security & privacy compliance resources and reports
ISO 27001:2022 Certificate
ISO 27001:2022 certificate (Certified by BSI, Expiry Date: July 3, 2026)
PCI-DSS v4.0.1 Certificate
PCI-DSS v4.0.1 certificate (Certified by SISA, Expiry Date: April 29, 2026)
PCI-DSS Attestation of Compliance (AoC) Report
This document provides the official Attestation of Compliance (AOC) with the Payment Card Industry Data Security Standard (PCI-DSS). It confirms that our systems, processes, and controls for handling, processing, and transmitting cardholder data have been independently assessed and validated by a Qualified Security Assessor (QSA). The attestation demonstrates our commitment to maintaining the highest level of payment security and compliance with industry requirements.
SOC 2 Type 1 Report
Period April 30, 2025 to October 30, 2025 (Audited and Issued by Ken & Co)
SOC 2 Type 1 Project Engagement Letter
This document outlines the formal engagement agreement between KompatoAI and our independent auditing firm for the SOC 2 Type 1 assessment. It defines the scope, objectives, and responsibilities of both parties during the audit process, ensuring transparency and accountability. The engagement letter confirms our commitment to undergo independent evaluation of our security, availability, confidentiality, processing integrity, and privacy controls in alignment with SOC 2 requirements.
SOC 2 Type 1 – Management Assertion Letter
This document provides KompatoAI’s formal management assertion for the SOC 2 Type 1 report. It affirms that the description of our systems is accurate and that the design of our security, availability, confidentiality, processing integrity, and privacy controls was in place as of the assessment date. This assertion is a required component of the SOC 2 Type 1 audit and reflects our commitment to maintaining robust internal controls in alignment with the Trust Services Criteria.
SOC 2 Type 2 Engagement Letter
This SOC 2 Type II Engagement Letter confirms the formal initiation of the audit and affirms that our organization’s control environment is designed and operated in alignment with the five SOC 2 Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
SOC2 Type 2 Management Representation Letter
The SOC 2 Type II Management Representation Letter provides formal assurance from management that the information and evidence supplied for the audit are accurate and complete, and that controls supporting the five Trust Services Criteria—Security, Availability, Processing Integrity, Confidentiality, and Privacy— have been properly designed and operated effectively throughout the review period.
SOC 2 Type 2 Certification
SOC 2 Type II Certification provides independent assurance that our organization’s controls are appropriately designed and have operated effectively over time in accordance with the SOC 2 Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
HIPAA Letter of Engagement
The HIPAA Letter of Engagement formally defines the scope, roles, and responsibilities for conducting an independent assessment of our compliance with applicable HIPAA Privacy, Security, and Breach Notification Rules.
Subprocessors
We engage carefully vetted subprocessors to support specific services, ensuring they meet our security, privacy, and compliance requirements.

AWS
Cloud Hosting Services
OpenAI
Cloud-based AI platform and large language model capability.

Interprose
a cloud-based debt collection and CRM platform that helps organizations streamline receivables management through automation, compliance, and secure digital engagement.

Twilio
A cloud communications platform that enables businesses to build and scale voice, messaging, video, and authentication services through flexible APIs.

TCN
An AI-powered platform built to elevate your contact center

Sendgrid
A cloud-based email delivery service used as a sub-processor to send transactional and notification emails securely and reliably to our customers.

Nuvei
A trusted payment processing provider, enabling secure and compliant handling of customer payment transactions in alignment with PCI-DSS standards.
