Skip to content
Legal Center

KokuaOS — Security Policy

Effective July 18, 2026 · Version 1.1

A public, non-confidential overview of the security program and controls KokuaOS uses to protect the Platform and the data it processes, and the responsibilities customers share.

Capitalized terms have the meanings in the KokuaOS Definitions Schedule (kokuaos.com/legal/definitions).

1. Purpose and scope

This Security Policy summarizes the technical and organizational measures KokuaOS uses to protect the Platform, the Services, and the data processed through them. It is written for a public audience and is intentionally general; it does not disclose confidential security details, and it is not a specification, a warranty, or a guarantee. KokuaOS maintains more detailed internal standards and may make additional information available to enterprise Customers under confidentiality through the Trust Center (/trust). Security is a shared responsibility; the controls below work together with the customer responsibilities in Section 15 and with the Compliance & Shared Responsibility Policy (kokuaos.com/legal/shared-responsibility). Where this Policy and an executed Agreement or Data Processing Addendum address the same subject, the Agreement or DPA controls.

2. Security governance

KokuaOS maintains a documented information-security program with defined ownership, written policies and standards, and periodic review. Personnel are subject to confidentiality obligations, receive security-awareness training appropriate to their role, and are granted access on a least-privilege, need-to-know basis. KokuaOS performs risk assessments and applies role-appropriate screening for personnel with access to production systems, consistent with applicable law.

3. Tenant isolation and multi-tenancy

The Platform is a hosted, multi-tenant environment. KokuaOS uses logical controls designed to segregate each tenant's data and configuration and to prevent one tenant from accessing another tenant's data. Access to tenant data is mediated by application-layer authorization and account scoping so that Authorized Users see only the accounts and resources for which they are provisioned within the commercial hierarchy.

4. Encryption

KokuaOS encrypts Customer Data in transit over public networks using current, industry-standard transport encryption (such as TLS), and encrypts Customer Data at rest using strong, industry-standard algorithms. Particularly sensitive values — such as integration credentials, API keys, and other secrets used to connect to Third-Party Services and BYO Providers — are additionally protected with field-level (application-layer) encryption so that they are not stored in plain text. Encryption keys are managed through a dedicated key-management process with restricted access and periodic rotation.

5. Access control and authorization (RBAC)

The Platform enforces role-based access control (RBAC) so that permissions follow defined roles across the Master Admin, Service Provider, Reseller, Customer, and Authorized User levels. Internally, administrative access to production systems is restricted to authorized personnel, granted on a least-privilege basis, logged, and reviewed periodically, with access promptly revoked upon role change or separation.

6. Authentication (MFA and SSO)

KokuaOS supports strong authentication for access to the Platform, including multi-factor authentication (MFA) and, for eligible plans, single sign-on (SSO) through supported identity providers. Customers and partners are responsible for enabling and enforcing MFA and SSO for their Authorized Users and for configuring their identity settings appropriately (see Section 15).

7. Logging and monitoring

KokuaOS maintains logging and monitoring designed to record relevant security and system events, detect anomalous or unauthorized activity, and support investigation and response. Logs are protected against tampering and retained for a period appropriate to their purpose. Alerting is configured for defined security-relevant conditions and is integrated with the incident-response process described in the Incident Response Policy (kokuaos.com/legal/incident-response).

8. Vulnerability management

KokuaOS operates a vulnerability-management process that includes patching of systems and dependencies, and periodic vulnerability assessment and testing of the Platform, which may include internal testing and the use of qualified third parties. Identified vulnerabilities are triaged by risk and remediated on a risk-prioritized timeline. KokuaOS also welcomes reports from external researchers under the Vulnerability Disclosure Policy (kokuaos.com/legal/vulnerability-disclosure).

9. Secure development

KokuaOS follows a secure software-development lifecycle. Changes are subject to version control, peer code review, testing, and a controlled release process, with separation between development, testing, and production environments. Security considerations are incorporated into design and review, and automated checks are used to help identify insecure code and vulnerable dependencies before release.

10. Secrets management

Application secrets, credentials, and keys are stored in protected secret stores rather than in source code, are access-controlled, and are rotated on a defined basis or upon suspected compromise. Customer-supplied credentials for BYO Providers and integrations are protected as described in Section 4.

11. Backups, resilience, and recovery

KokuaOS maintains backup and recovery processes designed to preserve the availability and integrity of the Platform and Customer Data and to support recovery from failures. Backups are protected consistent with the data they contain. KokuaOS maintains business-continuity and disaster-recovery practices appropriate to the Services. Availability commitments, if any, are governed by the Support & SLA Policy (kokuaos.com/legal/sla) and the applicable Order Form, not by this Policy.

12. Incident response

KokuaOS maintains a documented incident-response process for detecting, triaging, containing, investigating, and remediating security incidents, and for notifying affected customers where legally or contractually required. That process, including the customer's duty to promptly report suspected compromise, is described in the Incident Response Policy (kokuaos.com/legal/incident-response).

13. Vendor and subprocessor management

KokuaOS performs risk-based due diligence on service providers that support the Platform and imposes contractual confidentiality and data-protection obligations appropriate to their role. KokuaOS Subprocessors that process Personal Data on KokuaOS's behalf are described in the Subprocessor Policy (kokuaos.com/legal/subprocessors). BYO Providers selected and controlled by a Customer or Service Provider are Third-Party Services, are not KokuaOS Subprocessors, and are the responsibility of the party that selects them.

14. Data retention and deletion

KokuaOS retains and deletes Customer Data in accordance with the Agreement, the Data Processing Addendum, and the Privacy Policy (kokuaos.com/legal/privacy), including the post-termination export window described in the Master Terms & Conditions, subject to legal, security, backup, and payment exceptions. Deletion from active systems is followed by expiry from backups on their ordinary cycle. Consistent with the Master Terms & Conditions and the Data Processing Addendum, KokuaOS may retain data where reasonably necessary for security and fraud investigations and for legal hold or litigation, until the retention purpose ends.

15. Customer and partner responsibilities

Security depends on how the Services are configured and used. Customers, Service Providers, Resellers, and their Authorized Users are responsible for:

  • Credential security — safeguarding account credentials and API keys, keeping them confidential, and promptly rotating or revoking them on suspected compromise;
  • Access and RBAC configuration — provisioning Authorized Users appropriately, applying least privilege, and promptly removing access that is no longer needed;
  • MFA and SSO adoption — enabling and enforcing MFA and, where available, SSO, and maintaining the security of their identity providers;
  • Secure integrations and BYO Providers — securing their own systems, endpoints, integrations, and BYO Providers, including the credentials, configuration, availability, and compliance of those providers;
  • Appropriate use of the data — configuring disclosures, consent, recording, and data-handling controls (including the Compliance Shield) for their use case, and not submitting data types the Agreement prohibits (such as PHI outside an approved, BAA-covered use case, or full cardholder data outside an approved payment workflow); and
  • Their own security program — maintaining security controls appropriate to their environment and monitoring their own use of the Services.

16. Compliance status; no unearned certifications

KokuaOS aligns its security program with widely recognized industry frameworks and designs its controls to support customers' compliance programs. KokuaOS does not represent that it holds any particular certification, attestation, or audit report — such as SOC 2, ISO/IEC 27001, PCI DSS, or HIPAA compliance — unless that status is expressly stated in a signed writing or published on the Trust Center. Use of the Platform does not by itself make any party compliant with any law or standard. The current status of any audits, attestations, or reports is published at the Trust Center (/trust).

17. No guarantee of security

NO SECURITY PROGRAM IS PERFECT. WHILE KOKUAOS USES COMMERCIALLY REASONABLE MEASURES DESIGNED TO PROTECT THE PLATFORM AND THE DATA IT PROCESSES, THE KOKUAOS PARTIES DO NOT GUARANTEE THAT THE SERVICES OR ANY DATA WILL BE FREE FROM UNAUTHORIZED ACCESS, LOSS, OR OTHER SECURITY EVENTS, AND DO NOT WARRANT THAT THE SERVICES WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE. THIS POLICY DESCRIBES CONTROLS; IT DOES NOT CREATE A WARRANTY OR EXPAND ANY OBLIGATION OR LIABILITY BEYOND WHAT THE AGREEMENT EXPRESSLY STATES. THE DISCLAIMERS AND LIMITATIONS OF LIABILITY IN THE AGREEMENT GOVERN AND ARE NOT MODIFIED BY THIS POLICY.

18. Reporting and contact

To report a suspected security issue or vulnerability, contact security@kokuaos.com and follow the Vulnerability Disclosure Policy (kokuaos.com/legal/vulnerability-disclosure). For general security questions, or to request additional security information under confidentiality, contact your KokuaOS representative or visit the Trust Center (/trust). KokuaOS may update this Policy from time to time as described in the Master Terms & Conditions; the current version is published at /legal/security.

See it liveBook a demo