Kontakt.io · Trust Center
Kontaktio Trust Center
Trust center
Kontakt.io maintains a public trust center documenting SOC 2 Type II, HIPAA Security Rule / HITECH, GDPR, and ISO 27001 compliance.
CompanyIoTRTLSHealthcareAsset TrackingLocationOccupancyBluetoothDevice ManagementTelemetrySensorsStreaming
Certifications & Compliance
SOC 2 Type IIHIPAA Security Rule / HITECHGDPRISO 27001
Source
Trust Center
generated: '2026-08-23'
method: searched
source: https://trust.kontakt.io/ and https://kontakt.io/legal-documents/security/
trust_center:
url: https://trust.kontakt.io/
platform: Vanta
http_status: 200
probed: '2026-08-23'
note: Canonical Vanta-hosted trust center (canonical link rel points at https://trust.kontakt.io;
assets served from assets.vanta.com). Document access is request-gated behind Vanta,
which is normal for this platform — the certification claims below are read from
Kontakt.io's own public security page, not from gated Vanta artifacts.
security_page: https://kontakt.io/legal-documents/security/
security_officer: Lemlem Kentiba, Security & Compliance Officer
certifications:
- name: SOC 2 Type II
status: compliant
source: https://kontakt.io/legal-documents/security/
- name: HIPAA Security Rule / HITECH
status: compliant
source: https://kontakt.io/legal-documents/security/
- name: GDPR
status: aligned
source: https://kontakt.io/legal-documents/security/
- name: ISO 27001
status: not-claimed
source: Absent from the security page and the trust center landing page.
controls:
encryption_in_transit: TLS 1.2+ across all external and internal communications.
encryption_at_rest: AWS S3 encryption, encrypted EBS volumes, encrypted RDS/Aurora
databases and encrypted backups.
key_management: AWS KMS with FIPS 140-2 validated hardware security modules; key
access is role-restricted and monitored.
penetration_testing: External penetration tests conducted regularly by independent
third parties; findings undergo formal tracking and remediation.
vulnerability_disclosure:
program: false
note: 'No vulnerability disclosure program, bug bounty, or responsible-disclosure
contact was found. There is no /.well-known/security.txt on any Kontakt.io host,
no HackerOne/Bugcrowd/Intigriti presence, and the public security page names a
Security & Compliance Officer but publishes no security contact address. The only
reporting route is general support at https://support.kontakt.io/hc/en-gb/requests/new.
This is the single clearest security-posture gap for a vendor holding SOC 2 Type
II and HIPAA. No Security / VulnerabilityDisclosure pointer is emitted.'
evidence:
- url: https://kontakt.io/.well-known/security.txt
status: 404
- url: https://developer.kontakt.io/.well-known/security.txt
status: 404
- url: https://kontakt.io/legal-documents/security/
status: 200
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/kontaktio-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.