Skip to content
Trust Center

KokuaOS — Compliance Overview

Effective July 18, 2026 · Version 1.0

A plain-English summary of the KokuaOS compliance posture and the shared-responsibility model, provided for procurement, risk, and compliance teams.

Capitalized terms have the meanings in the KokuaOS Definitions Schedule (kokuaos.com/legal/definitions).

1. Our compliance philosophy

KokuaOS provides configurable controls and features that are designed to support our Customers' compliance programs. Two principles guide everything on this page:

  1. Designed to support, not a guarantee. We build tools — including the Compliance Shield for disclosures, consent, verification, recording, and data-handling controls — that help Customers operate in regulated contexts. Using the Platform does not, by itself, make any organization compliant with any law or framework.
  2. Compliance is a shared responsibility. KokuaOS is responsible for the security and operation of the Platform; the Customer is responsible for how it configures and uses the Services and for its own legal obligations. Section 2 sets out the split.

We describe our certification status honestly. KokuaOS does not claim to be certified or compliant with any framework except where we expressly say so in a signed writing. See the Compliance & Shared Responsibility Policy (kokuaos.com/legal/shared-responsibility) for the binding terms, which control if anything here appears to differ.

2. The shared-responsibility model

KokuaOS is generally responsible forThe Customer is generally responsible for
Securing and operating the Platform and its infrastructureDetermining what laws and frameworks apply to its use
Providing configurable compliance controls (Compliance Shield, RBAC, recording and disclosure settings)Configuring and enabling those controls correctly for its use case
Encryption, access control, monitoring, and incident response at the Platform layerManaging Authorized Users, roles, credentials, and MFA/SSO enforcement
Offering a DPA, Subprocessor transparency, and (where approved) a BAAEstablishing legal basis, notices, consent, and recording disclosures for its end users
Metering and recording Usage EventsData classification, minimization, retention choices, and human review of AI Output
Acting as processor / service provider for Customer end-user dataActing as controller / business and meeting its own regulatory duties

3. Framework-by-framework posture

The table below states our current posture. "Not certified" means we have not obtained the named certification; it does not describe the strength of the underlying controls, which are covered in the Security Overview (kokuaos.com/trust/security).

FrameworkKokuaOS postureStatus
HIPAA / HITECHPHI is prohibited by default. A HIPAA-enabled deployment is available only with KokuaOS approval of the use case, architecture, providers, retention, and procedures, and a signed BAA. HIPAA has no government certification.Available on approved deployment with signed BAA
PCI DSSKokuaOS is not a payment processor and is not a PCI-certified service provider. Full cardholder data must not enter prompts, recordings, transcripts, logs, or Knowledge Bases outside an expressly approved payment workflow.Not certified — full card data not accepted by default
GDPR / UK GDPRDPA available with international-transfer mechanisms; KokuaOS generally acts as processor for Customer end-user data.Supported via DPA — processor role
CCPA / CPRAKokuaOS contracts as a service provider and does not sell Personal Data.Supported via DPA — service-provider role
PIPEDAAddressed through our Privacy Policy and DPA commitments.Supported via privacy program and DPA
SOC 2 (Type II)Security program designed around SOC 2 principles; no examination completed and no report available.Roadmap — not certified
ISO/IEC 27001Information-security practices designed with ISO/IEC 27001 in mind.Roadmap — not certified
GLBAControls can support a financial-institution Customer's safeguards program; the Customer remains responsible for GLBA compliance.Customer-responsibility; controls designed to support
FINRA / SEC / SOXRecording, retention, and access controls are configurable to support supervision and recordkeeping; the Customer owns its regulatory obligations, supervision, and archiving.Customer-responsibility; controls designed to support
FERPAThe Customer (educational agency/institution) remains responsible for FERPA obligations; KokuaOS acts under Customer direction.Customer-responsibility
CJISKokuaOS does not currently represent that the Platform meets CJIS Security Policy requirements. Do not process CJIS-regulated data without a separate written agreement.Not supported by default
TCPAThe Compliance Shield supports consent capture and disclosures; the Customer owns consent, calling-time, and do-not-call obligations.Customer-responsibility; controls designed to support
CAN-SPAMMessaging features can support required disclosures and opt-out; the Customer owns sender identification, opt-out honoring, and content.Customer-responsibility; controls designed to support
Call recording / wiretapping (one- and two-party consent)The Compliance Shield supports recording disclosures and consent; the Customer determines the applicable consent standard by jurisdiction and configures accordingly.Customer-responsibility; controls designed to support
State and emerging AI laws (e.g., bot-disclosure and automated-decision rules)The Compliance Shield supports AI-disclosure and transparency; the Customer determines and configures required disclosures.Customer-responsibility; controls designed to support
Employment and consumer-protection lawsThe Customer is responsible for lawful use of AI Employees in hiring, credit, housing, and similar contexts, including human review of high-risk decisions.Customer-responsibility

4. Customer responsibilities

To use the Platform in a regulated context, Customers are responsible for, among other things:

  • Legal basis and notices for collecting and processing Personal Data.
  • Consent and recording disclosures, including the applicable one- or two-party consent standard.
  • Role permissions and least-privilege administration of Authorized Users.
  • Verification and authentication of callers and end users where required.
  • Retention and deletion decisions for Customer Data.
  • Data classification and minimization, including honoring the PHI and cardholder-data restrictions.
  • Knowledge and prompts — ensuring uploaded content and instructions are lawful and appropriate.
  • Third-party and BYO Provider selection, and any agreements those providers require.
  • Geographic restrictions and data-residency decisions for the Customer's use case.
  • Human review of AI Output before relying on it for high-risk or legally significant decisions.
  • Workforce training on lawful and appropriate use of the Services.
  • Incident response within the Customer's own environment, and prompt reporting of suspected compromise to KokuaOS.

5. HIPAA

PHI is prohibited by default on the Platform. A Customer that wishes to process PHI must request a HIPAA-enabled deployment; KokuaOS must approve the use case, architecture, providers, retention, and operating procedures; and a separate BAA must be signed where applicable. Any BYO Provider used in a HIPAA deployment must independently support HIPAA and sign the agreements it requires. Compliance remains shared, and the Customer stays responsible for its own HIPAA obligations. See the HIPAA / BAA Eligibility Notice (kokuaos.com/legal/hipaa).

6. PCI DSS

KokuaOS is not a payment processor. Full cardholder data must not be placed in prompts, call or message recordings, transcripts, logs, or Knowledge stores, and must not otherwise be processed on the Platform except through an expressly approved payment workflow. Customers needing to handle payments should use an approved, tokenized workflow so that full card data does not enter the Services.

7. What KokuaOS is not

Unless separately agreed in writing, KokuaOS is not the Customer's legal counsel, auditor, healthcare provider, payment processor, telecommunications carrier, or compliance consultant, and does not provide legal, regulatory, or compliance advice. Our controls are tools; the Customer's compliance outcomes depend on how the Customer configures and uses them and on the Customer's own program.

8. About this page

This Compliance Overview is provided for information and transparency. It describes our posture as of the date above and may change as our program and the law evolve. It is not a certification, warranty, or representation of compliance with any framework, and it does not modify any agreement. The binding terms are the KokuaOS Agreement and the Compliance & Shared Responsibility Policy at /legal/shared-responsibility. For questions, contact legal@kokuaos.com.

See it liveBook a demo