Kraken Technologies · Trust Center

Kraken Technologies Trust Center

Trust center

Kraken Technologies maintains a public trust center documenting ISO/IEC 27001:2022, SOC 1 Type 2, and SOC 2 Type 2 compliance.

EnergyUnited KingdomUtilitiesElectricityGasSmart MeteringDemand ResponseDERBillingEnergy Platform
Trust center: https://www.kraken.tech/legal/trust-center

Certifications & Compliance

ISO/IEC 27001:2022SOC 1 Type 2SOC 2 Type 2

Source

Trust Center

kraken-technologies-trust-center.yml Raw ↑
generated: '2026-07-27'
method: searched
probe: true
url: https://www.kraken.tech/legal/trust-center
source: https://www.kraken.tech/legal/trust-center
summary: >-
  Kraken publishes a substantive Trust Center inside its legal hub (not at trust.kraken.tech, which
  does not resolve — which is why the automated probe missed it). It names real certifications and
  attestations, describes the security architecture of the platform, and states that Kraken is a
  processor whose clients choose deployment region. Reports themselves are available to clients and
  prospects on request, not for anonymous download.
certifications:
- ISO/IEC 27001:2022
- SOC 1 Type 2
- SOC 2 Type 2
certification_detail:
- name: ISO/IEC 27001:2022
  scope: Information Security Management System (ISMS)
  verbatim: >-
    "Kraken holds ISO/IEC 27001:2022 certification and uses ISO27001 as the basis for our Information
    Security Management System."
- name: SOC 1 Type 2 / SOC 2 Type 2
  scope: Kraken Customer and Kraken Flex; Security, Availability and Confidentiality criteria
  cadence: Published twice annually
  verbatim: >-
    "Kraken's Customer and Kraken Flex maintain SOC 1 Type 2 and SOC 2 Type 2 attestations. These
    reports are published on a twice-annual basis to enable our clients with various reporting
    schedules to meet their necessary assurance needs."
pci_dss:
  kraken_certified: false
  model: delegated
  verbatim: >-
    "Credit card processing is not Kraken's mission. This is why we partner with trusted payment
    providers like Stripe to handle all payment transactions on your behalf... Your card details
    never touch Kraken's systems, and our payment partners (e.g. Stripe) are certified to the highest
    industry standards (PCI DSS Level 1)."
  note: >-
    Clients using their own payment provider carry their own PCI compliance. Kraken makes no PCI DSS
    certification claim for itself.
data_protection:
  gdpr_alignment: true
  verbatim: 'We align with General Data Protection Regulation (GDPR) take this as the standard across the business.'
  dpo: dpo@kraken.tech
  privacy_notice: https://www.kraken.tech/legal/privacy-notice
  cookie_notice: https://www.kraken.tech/legal/cookie-notice
  dpa: https://www.kraken.tech/legal/dpa
  subprocessors: https://www.kraken.tech/legal/subprocessors
  subprocessor_change_notification: true
  data_residency: >-
    Clients may deploy Kraken services in any supported region; Kraken will not relocate a client's
    workspace without prior consent.
  data_sale: 'Kraken does not sell client data or use it for advertising purposes.'
  transfer_impact_assessments: documented
security_architecture:
  hosting: Amazon Web Services
  tenancy: >-
    Kraken Customer Platform and Kraken Field Platform are single-tenant by default, with isolated
    network virtualisation, dedicated security controls, and optional log feeds into client SIEM
    tooling.
  encryption_at_rest: AES-256 (databases and other stores, e.g. S3)
  encryption_in_transit: Mandatory TLS 1.2+; known secure TLS 1.2 cipher suites and TLS 1.3
  sdlc: >-
    Secure SDLC integrated into CI/CD with SAST and Software Composition Analysis on every build, and
    vulnerability analysis before, during and after deployment.
  patching: Continuous deployment enabling >100 deployments daily, so patches reach client environments quickly.
  access_control:
  - Multi-factor authentication across Kraken access points (remote and in office)
  - Role-based access control with regular privileged access permission audits
  - Customisable roles and access levels
  - SAML integration with client identity providers for Kraken Customer Platform
  security_operations:
  - Continuous security monitoring
  - Threat detection with automation and machine learning
  - Regular security assessments
  - Incident response procedures and a dedicated security operations team
  - Disaster recovery capabilities
  employee_controls:
  - Mandatory security and privacy awareness training with annual refreshers
  - Role-specific security training based on job function and access level
  - Unique credentials per employee; regular privileged access review
report_access:
  anonymous_download: false
  channels: [Client Requests, Prospect Requests]
  note: SOC reports and assurance documentation are provided to clients and prospects on request.
evidence:
- source: https://www.kraken.tech/legal/trust-center
  status: 200
  date: '2026-07-27'
  keywords: [trust center, iso/iec 27001:2022, soc 1 type 2, soc 2 type 2, pci dss, gdpr, aes-256, tls 1.2, saml, dpo, subprocessors]
probes_that_missed:
- {host: trust.kraken.tech, dns: NXDOMAIN}
- {host: security.kraken.tech, dns: NXDOMAIN}
- {url: 'https://www.kraken.tech/legal/security', status: 200, note: 'legal links only — no certifications; the substance is at /legal/trust-center'}