Kota · Trust Center

Kota Trust Center

Trust center

Kota runs a hosted Trust Centre at trust.kota.io carrying full policies, ISO audit reports and real-time controls monitoring, backed by a detailed public security page. Certifications held by Kota itself are distinguished below from those inherited from its cloud hosting providers.

Kota maintains a public trust center documenting SOC 2, ISO 27001, HIPAA, and GDPR compliance.

CompanyFintechInsuranceEmployee BenefitsHealth InsurancePensionsInsurtechEmbedded FinanceHuman ResourcesPayroll
Trust center: https://trust.kota.io/

Certifications & Compliance

SOC 2ISO 27001HIPAAGDPR

Source

Trust Center

Raw ↑
generated: '2026-07-19'
method: searched
probe: true
source: https://www.kota.io/security, https://trust.kota.io/
url: https://trust.kota.io/
security_page: https://www.kota.io/security
description: >-
  Kota runs a hosted Trust Centre at trust.kota.io carrying full policies, ISO audit reports and
  real-time controls monitoring, backed by a detailed public security page. Certifications held by
  Kota itself are distinguished below from those inherited from its cloud hosting providers.
certifications:
- SOC 2
- ISO 27001
- HIPAA
- GDPR
certification_detail:
- name: ISO 27001:2022
  held_by: Kota
  status: audit completed
- name: GDPR
  held_by: Kota
  status: compliance committed; assists customers with their obligations
- name: PCI DSS
  held_by: Stripe (payment processor)
  status: card processing delegated to Stripe at PCI Level 1; Kota stores no card data
- name: SOC 1
  held_by: Microsoft Azure (hosting)
  status: inherited from infrastructure provider
- name: SOC 2
  held_by: Microsoft Azure (hosting)
  status: inherited from infrastructure provider
- name: SOC 3
  held_by: Microsoft Azure (hosting)
  status: inherited from infrastructure provider
- name: HIPAA
  held_by: Microsoft Azure (hosting)
  status: supported by infrastructure provider
hosting:
  regions: EU
  providers:
  - Microsoft Azure
  - Google Cloud Platform
security_controls:
  encryption_at_rest: AES256, with additional at-work encryption in the database
  encryption_in_transit: 256-bit SSL / TLS 1.3, using both ECDSA and RSA algorithms
  https_enforced: true
  security_headers:
  - X-Frame-Options
  - X-XSS-Protection
  - Content-Security-Policy
  backups: daily automated backups, full redundancy and disaster recovery
  access_control: employee access to customer data strictly limited and audited
  logging: detailed log collection for incident investigation
  vulnerability_management: automated vulnerability monitoring across all code; continuous updates
  mfa: RFC 6238-compatible authenticator app 2FA (shipped v4.2.6, 2026-04-08)
evidence:
- source: https://www.kota.io/security
  keywords:
  - soc 2
  - iso 27001
  - hipaa
  - trust center
  - trust centre
  - gdpr
- source: https://trust.kota.io/
  keywords:
  - trust center
related:
  vulnerability_disclosure: security/kota-vulnerability-disclosure.yml
  conformance: conformance/kota-conformance.yml

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/kota-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.