Company
Security
Kompendra will be assessed by your regulator as part of your systems. It is built to the standard you are held to.
Hosting and data residency
Kompendra runs on Google Cloud in the me-central1 region, in Doha, Qatar. All of your data stays in that region, including evidence files, backups and audit-log exports. TODO(Miles): confirm residency wording
Sign-in runs on a self-hosted identity service in the same region, so login data stays there too.
The only data that leaves the region is the text sent to our AI model provider when AI suggestions are switched on. This is disclosed in the data processing agreement, and you can switch AI off for your firm.
Encryption
- In transit: TLS 1.2 or higher.
- At rest: the database and object storage are encrypted.
- Evidence files are encrypted with tenant-level keys.
Access control
- Sign-in uses a self-hosted Keycloak identity service. Kompendra does not handle passwords itself.
- Multi-factor authentication is required for the Admin, Compliance and MLRO roles.
- Single sign-on through SAML or OIDC connects to your own identity provider. It is included on every plan.
- Session timeout is configurable.
- Access is role-based at firm, entity and module level. Built-in roles are Admin, Compliance, Risk, Business user, Board (read only), Auditor (read only, time-boxed) and Regulator (read only, time-boxed, limited to a pack).
- Restricted registers, such as the planned SAR/STR register, have their own access list, and every read is logged.
Tenant isolation
Every table in the database is protected by row-level security on the tenant. Automated tests assert that one firm’s data cannot be read by another.
Audit log
Every change is an append-only event with actor, time in UTC, action, and the state before and after. The database gives no update or delete rights on the audit table. The log is exported nightly to write-once storage.
Evidence integrity
Every file is stored under its SHA-256 hash and is never overwritten. A replacement is a new version. The hash is printed on every export.
Backups
Backups run daily and are kept for 35 days. Restores are tested every quarter, and each test is logged as evidence in Kompendra’s own tenant.
Penetration testing
A penetration test is carried out before our first paying customer and every year after that. Findings are tracked to closure in Kompendra itself.
Certification
We are working towards ISO 27001 and run our own control library in Kompendra. We do not hold the certification today. TODO(Miles): confirm you want to publish the ISO 27001 target
Retention and exit
Retention is set per firm. Deletion after the retention period is a logged action. When you leave, you receive an export of all your data.
Reporting a vulnerability
TODO(Miles): security contact email for vulnerability reports