Security is foundational to everything we build. Kaluta KYC handles some of the most sensitive data that exists — government IDs and biometrics — and we protect it with controls designed to meet the expectations of regulated industries such as banking, fintech, and insurance.
Encryption everywhere
TLS 1.2+ in transit and AES-256 at rest for all documents and biometric data.
Hashed credentials & keys
Passwords and API keys are stored using bcrypt; raw keys are shown only once.
Least-privilege access
Role-based access control with audit logging on every administrative action.
Isolated storage
Documents are stored in encrypted object storage and served via short-lived signed URLs.
Signed webhooks
Every webhook is signed with HMAC-SHA256 so you can verify authenticity.
Continuous monitoring
Automated fraud detection, anomaly alerts, and 24/7 infrastructure monitoring.
Compliance & certifications
- SOC 2 Type II — independently audited controls for security and availability.
- ISO/IEC 27001 — information security management system.
- GDPR & UK GDPR — full data-subject rights and lawful processing.
- PIPEDA — compliant with Canadian federal privacy law.
- AML/KYC — designed to support FINTRAC, FinCEN, and EU AML directives.
Data residency
We can host verification data in the region appropriate to your regulatory needs. International transfers, where applicable, are governed by Standard Contractual Clauses.
Responsible disclosure
We welcome reports from security researchers. If you believe you've found a vulnerability, please email security@kalutakyc.com. We commit to acknowledging reports promptly and will not pursue legal action against good-faith research.
Sub-processors & DPA
A list of sub-processors and our Data Processing Agreement are available to Customers on request. Contact security@kalutakyc.com.