KERVALT / SECURITY
Security built in at every level.
Kervalt uses multiple independent security layers across infrastructure, applications, and data. Every control is documented, tested, and available for enterprise review.
01 / OVERVIEW
How we secure your data
From physical infrastructure to who can log in, security is built in—not added later.
Encryption everywhere
AES-256 encryption at rest and TLS 1.3 in transit. Customer-managed keys available for enterprise deployments.
Identity & access management
Single sign-on, role-based access controls, multi-factor authentication, and detailed audit logging.
Network isolation
Private cloud deployment options, private endpoints, IP allowlisting, and air-gapped configurations.
Vulnerability management
Continuous scanning, dependency tracking, patch commitments, and third-party penetration testing at least annually.
Incident response
24/7 monitoring, clear escalation plans, and customer notification procedures aligned with GDPR timelines.
Secure development lifecycle
Code review, static analysis, secret scanning, and signed builds for every production release.
02 / DEPLOYMENT
Deployment models
Choose the deployment model that matches your risk, compliance, and performance requirements.
SAAS
Managed cloud
Kervalt-managed tenants on European infrastructure. Ideal for teams that need fast time-to-value with full data residency.
VPC
Private cloud
Dedicated virtual private environments with isolated networking and customer-controlled encryption keys.
ON-PREMISE
Air-gapped
Fully disconnected deployments for the highest security environments. No external network dependency.
03 / CERTIFICATIONS
Security certifications
Independent validation of our security management and AI governance.
ISO 27001
Information security management
ISO 42001
AI management systems
SOC 2 Type II
Security and availability controls
GDPR
Data protection by design
NEXT STEP
Need a deeper security review?
Our security team can walk you through architecture, controls, and audit evidence.