Security & Trust · Kintavo
SECURITY & TRUST

Your auditors will ask. Here are the answers.

Kintavo holds itself to the same standard it enforces for your quality system — audited, attested, and documented.

{{ c.name }} {{ c.badge }}
{{ c.desc }}

How your data is protected in practice.

{{ p.tag }}
{{ p.title }}
{{ p.desc }}
TRUST OPERATIONS
Subprocessors
A current list of subprocessors — cloud infrastructure, email delivery, and support tooling — is maintained and available on request, with notice before any addition.
Data residency
Production data is hosted in the United States by default, with regional hosting available for customers under EU or other data-residency requirements. Backups remain in-region.
Vulnerability disclosure
Found something? Report it to security@kintavo.com. Good-faith research is welcome — we commit to acknowledgment within 2 business days and no legal action for responsible disclosure.
Change transparency
Every release ships with validation documentation and customer-visible release notes — your change control can reference ours. Security-relevant changes are flagged explicitly.
ALL SYSTEMS OPERATIONAL · 99.99% UPTIME (TRAILING 12 MO)

Need the full security package?

SOC 2 report, penetration-test summary, validation documentation samples, and our BAA — under NDA, within one business day.

Request the security package
RELATED For IT & validation teams → 21 CFR Part 11 → About Kintavo →