Kraken Technologies · Trust Center
Kraken Technologies Trust Center
Trust center
Kraken Technologies maintains a public trust center documenting ISO/IEC 27001:2022, SOC 1 Type 2, and SOC 2 Type 2 compliance.
EnergyUnited KingdomUtilitiesElectricityGasSmart MeteringDemand ResponseDERBillingEnergy Platform
Trust center: https://www.kraken.tech/legal/trust-center
Certifications & Compliance
ISO/IEC 27001:2022SOC 1 Type 2SOC 2 Type 2
Source
Trust Center
generated: '2026-07-27'
method: searched
probe: true
url: https://www.kraken.tech/legal/trust-center
source: https://www.kraken.tech/legal/trust-center
summary: >-
Kraken publishes a substantive Trust Center inside its legal hub (not at trust.kraken.tech, which
does not resolve — which is why the automated probe missed it). It names real certifications and
attestations, describes the security architecture of the platform, and states that Kraken is a
processor whose clients choose deployment region. Reports themselves are available to clients and
prospects on request, not for anonymous download.
certifications:
- ISO/IEC 27001:2022
- SOC 1 Type 2
- SOC 2 Type 2
certification_detail:
- name: ISO/IEC 27001:2022
scope: Information Security Management System (ISMS)
verbatim: >-
"Kraken holds ISO/IEC 27001:2022 certification and uses ISO27001 as the basis for our Information
Security Management System."
- name: SOC 1 Type 2 / SOC 2 Type 2
scope: Kraken Customer and Kraken Flex; Security, Availability and Confidentiality criteria
cadence: Published twice annually
verbatim: >-
"Kraken's Customer and Kraken Flex maintain SOC 1 Type 2 and SOC 2 Type 2 attestations. These
reports are published on a twice-annual basis to enable our clients with various reporting
schedules to meet their necessary assurance needs."
pci_dss:
kraken_certified: false
model: delegated
verbatim: >-
"Credit card processing is not Kraken's mission. This is why we partner with trusted payment
providers like Stripe to handle all payment transactions on your behalf... Your card details
never touch Kraken's systems, and our payment partners (e.g. Stripe) are certified to the highest
industry standards (PCI DSS Level 1)."
note: >-
Clients using their own payment provider carry their own PCI compliance. Kraken makes no PCI DSS
certification claim for itself.
data_protection:
gdpr_alignment: true
verbatim: 'We align with General Data Protection Regulation (GDPR) take this as the standard across the business.'
dpo: dpo@kraken.tech
privacy_notice: https://www.kraken.tech/legal/privacy-notice
cookie_notice: https://www.kraken.tech/legal/cookie-notice
dpa: https://www.kraken.tech/legal/dpa
subprocessors: https://www.kraken.tech/legal/subprocessors
subprocessor_change_notification: true
data_residency: >-
Clients may deploy Kraken services in any supported region; Kraken will not relocate a client's
workspace without prior consent.
data_sale: 'Kraken does not sell client data or use it for advertising purposes.'
transfer_impact_assessments: documented
security_architecture:
hosting: Amazon Web Services
tenancy: >-
Kraken Customer Platform and Kraken Field Platform are single-tenant by default, with isolated
network virtualisation, dedicated security controls, and optional log feeds into client SIEM
tooling.
encryption_at_rest: AES-256 (databases and other stores, e.g. S3)
encryption_in_transit: Mandatory TLS 1.2+; known secure TLS 1.2 cipher suites and TLS 1.3
sdlc: >-
Secure SDLC integrated into CI/CD with SAST and Software Composition Analysis on every build, and
vulnerability analysis before, during and after deployment.
patching: Continuous deployment enabling >100 deployments daily, so patches reach client environments quickly.
access_control:
- Multi-factor authentication across Kraken access points (remote and in office)
- Role-based access control with regular privileged access permission audits
- Customisable roles and access levels
- SAML integration with client identity providers for Kraken Customer Platform
security_operations:
- Continuous security monitoring
- Threat detection with automation and machine learning
- Regular security assessments
- Incident response procedures and a dedicated security operations team
- Disaster recovery capabilities
employee_controls:
- Mandatory security and privacy awareness training with annual refreshers
- Role-specific security training based on job function and access level
- Unique credentials per employee; regular privileged access review
report_access:
anonymous_download: false
channels: [Client Requests, Prospect Requests]
note: SOC reports and assurance documentation are provided to clients and prospects on request.
evidence:
- source: https://www.kraken.tech/legal/trust-center
status: 200
date: '2026-07-27'
keywords: [trust center, iso/iec 27001:2022, soc 1 type 2, soc 2 type 2, pci dss, gdpr, aes-256, tls 1.2, saml, dpo, subprocessors]
probes_that_missed:
- {host: trust.kraken.tech, dns: NXDOMAIN}
- {host: security.kraken.tech, dns: NXDOMAIN}
- {url: 'https://www.kraken.tech/legal/security', status: 200, note: 'legal links only — no certifications; the substance is at /legal/trust-center'}