All systems operational

Trust Center

Security and compliance documentation for healthcare organizations evaluating Kustode.

HIPAA

Compliant

SOC 2 Type II

Certified

HITECH

Compliant

Security Controls

Data encrypted at rest
AES-256
Data encrypted in transit
TLS 1.3
Multi-factor authentication
Required for all users
Role-based access control
Least-privilege
Tenant data isolation
Continuously tested
PHI audit logging
Immutable, 6-year retention
Automated incident response
24-hour breach notification
Data residency
United States only
Backup & recovery
Continuous with point-in-time restore
Vulnerability management
Continuous automated scanning

SOC 2 Type II Report

Full audit report covering all five trust service criteria.

Under NDA

Business Associate Agreement (BAA)

Standard BAA template executed with every customer.

Request

Penetration Test Summary

Latest third-party penetration test executive summary.

Under NDA

Information Security Policy

Security controls, risk management, and governance.

Under NDA

Incident Response Plan

Detection, containment, recovery, and notification procedures.

Under NDA

Subprocessor List

Complete list of third-party vendors processing data.

Request

FAQ

Does Kustode sign BAAs?
Yes. We execute a Business Associate Agreement with every customer before any PHI is processed.
Where is my data stored?
All data is stored in the United States within HIPAA-eligible cloud services. Data never leaves the country. Each customer's data is logically isolated at the database layer.
Can I get a copy of the SOC 2 report?
Yes. Our SOC 2 Type II report is available under NDA. Contact security@kustode.com to request access.
What happens during a security incident?
Our team is alerted automatically. For breaches involving PHI, affected customers are notified within 24 hours per HIPAA breach notification requirements.
Does Kustode support SSO?
Yes. We support SAML 2.0 and OpenID Connect for single sign-on. Available on all plans.

Questions?

Our security team is available to answer questions and support your compliance review.