Data Processing & Security

How we handle your systems and your data during an engagement, written so IT and procurement can check it rather than take our word for it.

Effective Date: August 8, 2026

Our Security Commitment

We implement technical, physical and organizational measures proportionate to the work we do. We do not hold SOC 2 Type II or ISO 27001, and we do not claim them. Where a project touches health data, personal data or another regulated workload, we design against that regulation's requirements, HIPAA and GDPR included, and put the specifics in writing before the build starts. If a certification is a hard requirement for your procurement process, tell us early.

Industry-Specific Security

Healthcare

HIPAA-Aligned Practices

  • PHI handling procedures per 45 CFR Parts 160 and 164
  • Business Associate Agreements (BAAs) available
  • Encrypted ePHI in transit and at rest
  • Access controls and audit logging

Manufacturing

ISO-Aligned Controls

  • Quality management best practices
  • Data loss prevention (DLP) controls
  • Supply chain data protection
  • Segregated environments per client engagement

Technical Security Controls

Infrastructure Security

• Application hosting on Vercel; database, auth and storage on Supabase

• Network protection, TLS termination and DDoS mitigation as provided by those platforms

• Managed backups and point-in-time recovery per the platform's policy

• On-premises and private-cloud deployment where a project requires it

Application Security

• Secure development following OWASP Top 10

• Regular vulnerability scanning and code reviews

• Timely security patches and updates

• Encrypted credential storage

Data Security

• AES-256 encryption at rest

• TLS 1.3 encryption in transit

• Separate projects and credentials per client engagement

• Secure data deletion when retention ends

Access Controls

• Multi-Factor Authentication (MFA) required

• Role-based access control (RBAC)

• Least privilege principle

• Comprehensive audit logging

Flexible Data Residency

We understand that data location is critical for compliance. We offer flexible deployment options to meet your specific requirements:

Cloud Regions

India, EU, USA, or your preferred region

On-Premises

Local deployment for maximum control

Hybrid Solutions

Best of both based on your needs

Organizational Security

Personnel Security

  • Employee confidentiality agreements
  • Security awareness training
  • Immediate access revocation on offboarding
  • Background checks for sensitive roles

Incident Response

  • Defined incident response procedures
  • Designated response team
  • Breach notification per applicable law
  • Root cause analysis and remediation

Shared Responsibility

While we secure our systems and implement best practices, clients maintain responsibility for:

  • Access Authorization: Controlling who uses implemented systems
  • Activity Monitoring: Reviewing logs and alerts from deployed agents
  • Issue Reporting: Notifying us immediately of suspected security issues
  • Regulatory Compliance: Overall compliance responsibility remains with you

Security Incidents

If you suspect a security issue: we acknowledge within 1 business day and target a fix or a written status within 5 business days, depending on severity.

  1. 1. Immediately notify: security@kaizenlabs.co.in
  2. 2. Provide details: Nature of issue, affected data, timeline
  3. 3. Preserve evidence: Don't delete logs or modify systems
  4. 4. We will: Investigate, contain, remediate, and notify as required by law

Contact Us

For security or compliance inquiries:
Email: legal@kaizenlabs.co.in