Data Processing & Security
How we handle your systems and your data during an engagement, written so IT and procurement can check it rather than take our word for it.
Effective Date: August 8, 2026
Our Security Commitment
We implement technical, physical and organizational measures proportionate to the work we do. We do not hold SOC 2 Type II or ISO 27001, and we do not claim them. Where a project touches health data, personal data or another regulated workload, we design against that regulation's requirements, HIPAA and GDPR included, and put the specifics in writing before the build starts. If a certification is a hard requirement for your procurement process, tell us early.
Industry-Specific Security
Healthcare
HIPAA-Aligned Practices
- PHI handling procedures per 45 CFR Parts 160 and 164
- Business Associate Agreements (BAAs) available
- Encrypted ePHI in transit and at rest
- Access controls and audit logging
Manufacturing
ISO-Aligned Controls
- Quality management best practices
- Data loss prevention (DLP) controls
- Supply chain data protection
- Segregated environments per client engagement
Technical Security Controls
Infrastructure Security
• Application hosting on Vercel; database, auth and storage on Supabase
• Network protection, TLS termination and DDoS mitigation as provided by those platforms
• Managed backups and point-in-time recovery per the platform's policy
• On-premises and private-cloud deployment where a project requires it
Application Security
• Secure development following OWASP Top 10
• Regular vulnerability scanning and code reviews
• Timely security patches and updates
• Encrypted credential storage
Data Security
• AES-256 encryption at rest
• TLS 1.3 encryption in transit
• Separate projects and credentials per client engagement
• Secure data deletion when retention ends
Access Controls
• Multi-Factor Authentication (MFA) required
• Role-based access control (RBAC)
• Least privilege principle
• Comprehensive audit logging
Flexible Data Residency
We understand that data location is critical for compliance. We offer flexible deployment options to meet your specific requirements:
Cloud Regions
India, EU, USA, or your preferred region
On-Premises
Local deployment for maximum control
Hybrid Solutions
Best of both based on your needs
Organizational Security
Personnel Security
- Employee confidentiality agreements
- Security awareness training
- Immediate access revocation on offboarding
- Background checks for sensitive roles
Incident Response
- Defined incident response procedures
- Designated response team
- Breach notification per applicable law
- Root cause analysis and remediation
Shared Responsibility
While we secure our systems and implement best practices, clients maintain responsibility for:
- Access Authorization: Controlling who uses implemented systems
- Activity Monitoring: Reviewing logs and alerts from deployed agents
- Issue Reporting: Notifying us immediately of suspected security issues
- Regulatory Compliance: Overall compliance responsibility remains with you
Security Incidents
If you suspect a security issue: we acknowledge within 1 business day and target a fix or a written status within 5 business days, depending on severity.
- 1. Immediately notify: security@kaizenlabs.co.in
- 2. Provide details: Nature of issue, affected data, timeline
- 3. Preserve evidence: Don't delete logs or modify systems
- 4. We will: Investigate, contain, remediate, and notify as required by law
Contact Us
For security or compliance inquiries:
Email: legal@kaizenlabs.co.in