Skip to content
Trust Center

KokuaOS — Security Overview

Effective July 18, 2026 · Version 1.0

A plain-English summary of how KokuaOS protects the Platform and Customer Data, provided for security reviewers, procurement teams, and Customers.

Capitalized terms have the meanings in the KokuaOS Definitions Schedule (kokuaos.com/legal/definitions).

1. Our approach to security

Security is built into how we design, deploy, and operate the Platform. Our program applies administrative, technical, and physical safeguards that are designed to support the confidentiality, integrity, and availability of Customer Data, and we calibrate those safeguards to the sensitivity of the data and the risks we can reasonably foresee. This page summarizes those practices in plain English. For the binding statement of our safeguards, see the Security Policy (kokuaos.com/legal/security), which controls if anything here appears to differ.

Security on the Platform is a shared responsibility. KokuaOS secures the Platform and the infrastructure we operate; Customers and partners are responsible for how they configure and use the Services, including their credentials, user access, data choices, and any Third-Party or BYO Providers they bring. Section 12 describes the split.

2. Hosting and multi-tenant isolation

The Platform is a hosted, multi-tenant service operated on a leading enterprise cloud. Each tenant's data and configuration are logically isolated and access is tenant-scoped, so that one tenant's Authorized Users and AI Employees cannot reach another tenant's data through the Services. Isolation is enforced in the application and data layers and reinforced by the access controls described below. Our multi-tenant model lets us deliver consistent security updates, monitoring, and resilience to all Customers at once.

3. Encryption

  • In transit. Traffic to and within the Services is encrypted using industry-standard Transport Layer Security (TLS).
  • At rest. Customer Data is encrypted at rest using strong, industry-standard algorithms.
  • Secrets and credentials. Sensitive values, such as integration credentials and provider keys, receive field-level encryption and are isolated per entity, so that secrets are not shared or inherited across tenants or entities. Encryption keys are managed through our cloud provider's key management services and are subject to access controls and rotation practices.

4. Identity and access management

  • Role-based access control (RBAC). Access within the Platform is governed by roles and the four-tier commercial hierarchy (Master Admin, Service Provider, Reseller, Customer), so that administrators and Authorized Users receive only the privileges appropriate to their role.
  • Authentication. The Platform supports multi-factor authentication (MFA) and single sign-on (SSO) for administrative and user access, subject to plan and configuration. Customers are responsible for enabling and enforcing these controls for their own users.
  • Least privilege for KokuaOS personnel. Internal access to production systems and Customer Data is limited to personnel who need it to operate and support the Services, is granted on a least-privilege basis, and is logged. Personnel are subject to confidentiality obligations and security training.

5. Logging, monitoring, and detection

We maintain logging and monitoring across the Platform to help us detect, investigate, and respond to anomalous or unauthorized activity. Security-relevant events are recorded, and we use automated monitoring and alerting to surface potential issues to our team. Logs are retained for operational and security purposes consistent with our retention practices and applicable law.

6. Vulnerability management and secure development

  • Secure development. Security is integrated into our development lifecycle, including code review, testing, dependency management, and change-control practices designed to reduce the introduction of vulnerabilities.
  • Vulnerability management. We monitor for vulnerabilities in our systems and dependencies, assess and prioritize them by risk, and remediate them on a risk-based schedule. We apply security patches to systems under our control in a timely manner.
  • Coordinated disclosure. We welcome good-faith reports from security researchers. See our Vulnerability Disclosure Policy (kokuaos.com/legal/vulnerability-disclosure) for authorized scope, prohibited testing, and safe-harbor terms, or email security@kokuaos.com.

7. Secrets management

Application secrets, provider keys, and integration credentials are stored using dedicated secret- management practices, with field-level encryption and per-entity isolation so that no entity inherits another's secrets. Access to secrets is restricted, logged, and separated from general application data.

8. Backups, resilience, and disaster recovery

We maintain backups of Platform data and use the resilience features of our cloud infrastructure to support recovery and continuity of the Services. We maintain business-continuity and disaster-recovery practices designed to restore the Services within commercially reasonable objectives following a disruptive event. Availability targets and any service credits are addressed in the Support & SLA Policy (kokuaos.com/legal/sla).

9. Incident response

We maintain an incident-response program covering detection and triage, containment, investigation, remediation, evidence preservation, and post-incident review. Where a security incident affects Customer Data, we will notify affected Customers as required by applicable law and any signed Data Processing Addendum, and we will provide information reasonably necessary for the Customer to meet its own obligations. Customers must promptly report suspected compromised credentials or suspicious activity to security@kokuaos.com. See the Incident Response Policy (kokuaos.com/legal/incident-response).

10. Vendor and subprocessor management

We engage a limited set of Subprocessors and vendors to help deliver the Services and assess their security practices as part of our vendor-management process. Our current Subprocessors are listed, by function, location, and data type, in the Subprocessor Policy (kokuaos.com/legal/subprocessors), which also describes how we provide notice of changes. Third-Party Services and BYO Providers that a Customer or Service Provider selects and controls are not KokuaOS Subprocessors; the party that brings them is responsible for their security, credentials, and compliance.

11. Data retention and deletion

We retain Customer Data for as long as needed to provide the Services and as described in our Privacy Policy and the applicable Agreement. After termination, a Customer may export Customer Data for 30 days, after which KokuaOS may delete it, subject to legal, security, backup, and payment exceptions. Backup copies are deleted on a rolling cycle. See the Privacy Policy (kokuaos.com/legal/privacy) and the Compliance Overview (kokuaos.com/trust/compliance) for more detail.

12. Shared responsibility — your role

Security is most effective when both sides do their part. Customers and partners are responsible for, among other things:

  • Enabling and enforcing MFA and SSO, and managing their Authorized Users and role assignments.
  • Safeguarding account credentials and promptly reporting suspected compromise.
  • Configuring AI Employees, prompts, Knowledge Bases, recording, disclosure, and consent controls appropriately for their use case (including through the Compliance Shield).
  • Deciding what data to submit to the Services and classifying and minimizing sensitive data accordingly (including honoring the restrictions on PHI and full cardholder data).
  • Selecting, securing, and maintaining any Third-Party or BYO Providers they bring.
  • Complying with the Acceptable Use Policy and applicable law.

13. Certifications and roadmap

We describe our certification status honestly on the Trust Center. As of the date above, KokuaOS is not SOC 2 or ISO/IEC 27001 certified; those programs are on our roadmap. HIPAA-enabled deployments are available on approved architecture with a signed BAA, and full cardholder data is not accepted outside approved payment workflows. See the Trust Center — Certifications and roadmap (/trust) and the Compliance Overview (kokuaos.com/trust/compliance).

14. No guarantee of invulnerability

No product, service, or safeguard is perfectly secure. While we work hard to protect the Platform and Customer Data, KokuaOS does not and cannot guarantee that the Services will be uninterrupted, error-free, or invulnerable, or that our safeguards will prevent all unauthorized access, loss, or misuse. This overview describes practices in effect as of the date above, is provided for information only, and may change as our program evolves. It does not modify any agreement and does not create any warranty or commitment; the binding terms, including the disclaimers and limitations of liability, are in the KokuaOS Agreement and the Security Policy.

See it liveBook a demo