Skip to content
Legal Center

KokuaOS — Compliance & Shared Responsibility Policy

Effective July 18, 2026 · Version 1.0

How compliance responsibility is divided between KokuaOS (of the Platform) and the Customer (of its use), and how KokuaOS's configurable controls are designed to support Customer compliance programs.

Capitalized terms have the meanings in the KokuaOS Definitions Schedule (kokuaos.com/legal/definitions).

1. Purpose and core position

KokuaOS provides a hosted, multi-tenant Platform with configurable controls — including the Compliance Shield — that are designed to support Customer compliance programs. Use of the Platform alone does not establish, guarantee, or certify compliance with any law, regulation, or framework. Compliance depends on how each Customer, Service Provider, and Reseller configures and operates the Services, the data it processes, the jurisdictions and industries it serves, the consents and disclosures it obtains, and the human and organizational controls it maintains.

Accordingly, compliance is a shared responsibility: KokuaOS is responsible for the security and operation of the Platform it provides; each Customer (and each partner and its downstream Customers) is responsible for lawful, compliant use of the Platform. This Policy describes that split, addresses the frameworks Customers most often ask about, and states what KokuaOS is and is not. It is a Policy incorporated by reference into the Agreement and supplements the Security Policy (kokuaos.com/legal/security), the Privacy Policy (kokuaos.com/legal/privacy), the Data Processing Addendum (kokuaos.com/legal/dpa), and the Acceptable Use Policy (kokuaos.com/legal/aup).

2. The shared-responsibility model

The following table summarizes the general division of responsibility. It is a summary; the Agreement, the DPA, and applicable Order Forms control if more specific.

AreaKokuaOS (of the Platform)Customer / partner (of its use)
Platform securitySecure design, hosting, and operation of the Platform; the controls described in the Security PolicySecure use of the account; endpoint, network, and credential security on the Customer side
Access managementRole-based access features, authentication options, audit logging as offeredProvisioning and deprovisioning Authorized Users; setting roles/permissions; enforcing least privilege and MFA where available
Data content and classificationProcessing Customer Data to provide the Services per the Agreement and DPADeciding what data enters the Services; classifying data; keeping prohibited/regulated data out unless approved
Consent, notice, and disclosureConfigurable disclosure, consent, verification, and recording controls (Compliance Shield)Determining what consents/notices/disclosures the law requires and configuring, enabling, and delivering them
Communications complianceChannel and calling/messaging features; provider orchestrationTCPA/CAN-SPAM/Do-Not-Call/recording compliance for the Customer's campaigns and calls
AI oversightAI Services, safeguards, and guardrail configuration; the Responsible AI PolicyHuman review of AI Output; approving high-risk uses; monitoring outcomes
Third-party / BYO providersOrchestration across providers; Subprocessor management for KokuaOS-managed providersSelecting, contracting for, securing, and complying with any BYO Provider it brings
Retention and deletionRetention/export/deletion features and default behaviors described in the AgreementSetting retention/deletion to meet its legal obligations; exporting within the post-termination window
Incident responsePlatform-side detection and the Incident Response Policy (kokuaos.com/legal/incident-response)Customer-side incident response, breach analysis, and regulatory/individual notifications for its use

KokuaOS acts as a Subprocessor or processor only with respect to KokuaOS-managed providers. A BYO Provider that a Customer or Service Provider selects and controls is a Third-Party Service and is not a KokuaOS Subprocessor; the Customer or Service Provider is solely responsible for it, including its accounts, security, availability, and compliance.

3. Regulatory frameworks

For each framework below, KokuaOS offers features designed to support a Customer's own compliance program. None of the following is a representation that KokuaOS, the Platform, or any Customer is certified under or compliant with the framework, and none creates any obligation of KokuaOS beyond what is expressly stated in a signed writing.

  • HIPAA / HITECH. No Protected Health Information (PHI) may be processed through the Services unless KokuaOS has approved the use case, providers, and architecture in writing and a Business Associate Agreement is in place. See Section 5 and the HIPAA / BAA Eligibility Notice (kokuaos.com/legal/hipaa).
  • PCI DSS. Full cardholder data must not be placed in prompts, recordings, transcripts, logs, or Knowledge Base or other stores, except within an expressly approved payment workflow. See Section 6. KokuaOS is not a payment processor and does not assume a merchant's or service provider's PCI obligations.
  • GDPR / UK GDPR. The DPA governs processing of Personal Data subject to EU/UK data-protection law, including roles (controller/processor), Subprocessors, international-transfer mechanisms, and data-subject-request support. The Customer is the controller for its use unless the Agreement states otherwise.
  • CCPA / CPRA. KokuaOS processes Personal Data as a service provider to the Customer, as described in the DPA, and does not sell or share Personal Data or use it outside the Agreement. The Customer is the business responsible for its own consumer notices and rights handling.
  • PIPEDA. For Canadian Personal Data, KokuaOS provides features designed to support accountability, consent, and safeguard requirements; the Customer remains responsible for its PIPEDA obligations.
  • SOC 2 / ISO 27001. KokuaOS maintains a security program with controls designed to support recognized security frameworks. Any third-party attestation or certification KokuaOS holds or pursues, and its scope and status, are described in the Security Policy and the Trust Center (/trust); a KokuaOS attestation covers KokuaOS's Platform and does not extend to, or establish compliance for, a Customer's own use or systems.
  • GLBA. For financial-institution Customers, KokuaOS offers safeguards and configuration options designed to support GLBA Safeguards Rule and privacy obligations; the Customer remains the regulated financial institution responsible for compliance.
  • FINRA / SEC. KokuaOS is not a broker-dealer, investment adviser, or registered entity. Customers in securities-regulated activities are responsible for supervision, recordkeeping, communications-retention, and disclosure obligations (including any applicable books-and-records and communications-review rules).
  • SOX. KokuaOS does not assume any Customer's internal-control-over-financial-reporting obligations; the Customer is responsible for its own SOX controls and evidence.
  • FERPA. For educational-institution Customers, KokuaOS may act as a "school official" with a legitimate educational interest where the Agreement so provides; the Customer remains responsible for FERPA compliance and directory-information and consent decisions.
  • CJIS. Criminal-justice information must not be processed through the Services unless KokuaOS has expressly approved the use case and architecture in writing; absent that approval, CJIS-regulated data is prohibited data under the Acceptable Use Policy.
  • TCPA / CAN-SPAM / Do-Not-Call. KokuaOS provides calling and messaging features and configurable consent, identification, opt-out, and time-of-day controls; the Customer is solely responsible for the legality of its calling and messaging campaigns, including consent, caller-identification, and opt-out compliance.
  • Recording and wiretap laws. KokuaOS provides configurable recording and disclosure controls; the Customer is responsible for determining and obtaining the consents required by applicable one-party or all-party consent, wiretap, eavesdropping, and privacy laws before recording or monitoring.
  • State AI laws. KokuaOS provides disclosure and configuration features designed to support obligations under emerging U.S. state AI and automated-communication laws (including bot- and AI-disclosure and automated-decision requirements); the Customer is responsible for determining which such laws apply to its use and configuring the Services accordingly. See also the Responsible AI Policy.
  • Employment and consumer-protection laws. For hiring, HR, collections, advertising, or other regulated uses, the Customer is responsible for compliance with applicable employment, anti-discrimination, automated-decision, debt-collection, and consumer-protection laws, including any required human review, notices, and adverse-action procedures.

4. Customer responsibilities

Each Customer (and each Service Provider and Reseller for its own and its downstream use) is responsible for the following, and for ensuring its Authorized Users and downstream Customers do the same:

  • Legal basis and notices — establishing a lawful basis for its processing and providing all required privacy and other notices.
  • Consent and recording disclosures — obtaining and recording all consents and delivering all disclosures required before calling, messaging, recording, or monitoring.
  • Role permissions — provisioning Authorized Users, assigning roles and permissions, and enforcing least privilege.
  • Verification and authentication — configuring identity verification and authentication appropriate to its use.
  • Retention and deletion — setting retention and deletion controls to meet its legal and contractual obligations and exporting data within the post-termination window.
  • Data classification — classifying data and keeping prohibited or unapproved regulated data out of the Services.
  • Knowledge and prompts — ensuring its Knowledge Base content and prompts are accurate, lawful, and free of prohibited data.
  • Third-party provider selection — selecting and managing any BYO Provider and any integration, including its terms, security, and compliance.
  • Geographic restrictions — determining and configuring any data-residency, localization, or geographic restrictions its obligations require.
  • Human review — maintaining qualified human oversight of AI Output, especially for high-risk or legally significant decisions.
  • Workforce training — training its Authorized Users on lawful and appropriate use of the Services.
  • Incident response — maintaining its own incident-response process and making any breach or regulatory notifications required for its use.

5. HIPAA / PHI

The Services are not, by default, configured or authorized to process PHI. A Customer may process PHI through the Services only if all of the following are true: (a) KokuaOS has approved the specific use case in writing; (b) the Customer uses the architecture, configuration, and providers KokuaOS has approved for PHI; and (c) a Business Associate Agreement between the Customer and KokuaOS is in effect where one is required. Absent these conditions, PHI is prohibited data, and the Customer must not submit it to the Services. BYO Providers used for a PHI workflow must independently satisfy the Customer's HIPAA obligations. See the HIPAA / BAA Eligibility Notice.

6. PCI / cardholder data

The Customer must not place full cardholder data — including a full primary account number together with sensitive authentication data — into prompts, recordings, transcripts, logs, Knowledge Base content, or other stores. Payment-related use is permitted only through an expressly approved payment workflow (for example, one that tokenizes or redirects payment data to a compliant payment provider so that full cardholder data does not enter the Platform's general processing or storage). KokuaOS is not a payment processor and does not assume the Customer's or any provider's PCI DSS obligations.

7. What KokuaOS is not

Except to the extent expressly agreed in a separate signed writing, KokuaOS is not the Customer's legal counsel, auditor, healthcare provider or covered entity, payment processor, telecommunications carrier, or compliance consultant, and does not provide legal, regulatory, medical, financial, or professional advice. Materials KokuaOS provides — including this Policy, the Trust Center, templates, and the Compliance Shield — are informational and configurable tools; they are not a substitute for the Customer's own legal and compliance review. The Customer is responsible for determining which laws apply to its use and for meeting them.

8. Relationship to the Agreement

This Policy is incorporated into and forms part of the Agreement, and its defined terms have the meanings given in the Definitions Schedule. Nothing in this Policy expands KokuaOS's obligations beyond the Agreement or limits the disclaimers, limitations of liability, or indemnities in the Agreement, which continue to apply and which protect the KokuaOS Parties as intended third-party beneficiaries. If this Policy and the DPA or a signed BAA conflict on a matter each addresses, the DPA or BAA controls for that matter.

See it liveBook a demo