Kota · Trust Center

Kota Trust Center

Trust center

Kota runs a hosted Trust Centre at trust.kota.io carrying full policies, ISO audit reports and real-time controls monitoring, backed by a detailed public security page. Certifications held by Kota itself are distinguished below from those inherited from its cloud hosting providers.

Kota maintains a public trust center documenting SOC 2, ISO 27001, HIPAA, and GDPR compliance.

CompanyFintechInsuranceEmployee BenefitsHealth InsurancePensionsInsurtechEmbedded FinanceHuman ResourcesPayroll
Trust center: https://trust.kota.io/

Certifications & Compliance

SOC 2ISO 27001HIPAAGDPR

Source

Trust Center

Raw ↑
generated: '2026-07-19'
method: searched
probe: true
source: https://www.kota.io/security, https://trust.kota.io/
url: https://trust.kota.io/
security_page: https://www.kota.io/security
description: >-
  Kota runs a hosted Trust Centre at trust.kota.io carrying full policies, ISO audit reports and
  real-time controls monitoring, backed by a detailed public security page. Certifications held by
  Kota itself are distinguished below from those inherited from its cloud hosting providers.
certifications:
- SOC 2
- ISO 27001
- HIPAA
- GDPR
certification_detail:
- name: ISO 27001:2022
  held_by: Kota
  status: audit completed
- name: GDPR
  held_by: Kota
  status: compliance committed; assists customers with their obligations
- name: PCI DSS
  held_by: Stripe (payment processor)
  status: card processing delegated to Stripe at PCI Level 1; Kota stores no card data
- name: SOC 1
  held_by: Microsoft Azure (hosting)
  status: inherited from infrastructure provider
- name: SOC 2
  held_by: Microsoft Azure (hosting)
  status: inherited from infrastructure provider
- name: SOC 3
  held_by: Microsoft Azure (hosting)
  status: inherited from infrastructure provider
- name: HIPAA
  held_by: Microsoft Azure (hosting)
  status: supported by infrastructure provider
hosting:
  regions: EU
  providers:
  - Microsoft Azure
  - Google Cloud Platform
security_controls:
  encryption_at_rest: AES256, with additional at-work encryption in the database
  encryption_in_transit: 256-bit SSL / TLS 1.3, using both ECDSA and RSA algorithms
  https_enforced: true
  security_headers:
  - X-Frame-Options
  - X-XSS-Protection
  - Content-Security-Policy
  backups: daily automated backups, full redundancy and disaster recovery
  access_control: employee access to customer data strictly limited and audited
  logging: detailed log collection for incident investigation
  vulnerability_management: automated vulnerability monitoring across all code; continuous updates
  mfa: RFC 6238-compatible authenticator app 2FA (shipped v4.2.6, 2026-04-08)
evidence:
- source: https://www.kota.io/security
  keywords:
  - soc 2
  - iso 27001
  - hipaa
  - trust center
  - trust centre
  - gdpr
- source: https://trust.kota.io/
  keywords:
  - trust center
related:
  vulnerability_disclosure: security/kota-vulnerability-disclosure.yml
  conformance: conformance/kota-conformance.yml