Security, compliance, and data protection at Kolva. Everything you need to evaluate our platform for your organization.
Security and control
Your ERP data remains governed by your organization. Kolva applies controlled access, human validation, and revocable permissions across the intelligence layer.
ERP agents use read-only source access unless a separately scoped action is explicitly enabled.
Transport and storage protections cover data moving through Kolva and data persisted by the platform.
User, role, company, and data scopes determine which context and actions are available.
Discovery workflows minimize and sanitize technical metadata before support analysis.
Support interventions follow a controlled workflow with actor, scope, and timing context.
Permission-gated actions inside Kolva require explicit authorization and human validation. The standard ERP synchronization path remains outbound and read-only.
Customers retain control over connector, user, token, and assistant access revocation.
Compliance Status
Type I in progress — Type II to follow. Audit logging enabled, all user actions tracked, immutable logs with 36-month retention. Service Organization Control audit covering security, availability, and confidentiality.
Full compliance with the EU General Data Protection Regulation. DPA available for all customers.
California Consumer Privacy Act compliance. Data access, deletion, and opt-out rights fully supported.
Information security management system certification. On the roadmap for 2027.
Kolva does not process protected health information (PHI). Not in scope.
Data Handling
Primary region: EU (AWS eu-west-1, Ireland). Any alternate residency requirement is reviewed contractually before rollout.
AES-256 at rest for all stored data. TLS 1.3 in transit for every API call, webhook, and agent sync.
Configurable per company. Default: 36 months. Data deletion on request within 30 days. Full GDPR export.
Daily automated backups with point-in-time recovery. 30-day backup retention. Encrypted in transit and at rest.
ERP agents run on your corporate network. Data stays local until synced over HTTPS. No inbound ports required.
The standard ERP synchronization path is outbound-only and requires no inbound ports. Separately enabled sensitive actions use explicit, permission-gated workflows outside this default read path.
Sub-processors
| Provider | Purpose | Location | Compliance |
|---|---|---|---|
| Supabase | Database & Authentication | AWS EU (Ireland) | SOC 2 |
| Vercel | Hosting & CDN | Global Edge | SOC 2 |
| Stripe | Payment Processing | US / EU | PCI DSS Level 1 |
| Resend | Transactional Email | US | SOC 2 |
| Anthropic | AI Processing (Claude) | US | SOC 2 |
| OpenAI | Speech Processing (Whisper) | US | SOC 2 |
| Inngest | Task Orchestration | US | SOC 2 |
| Upstash | Rate Limiting & Caching | Global | SOC 2 |
Last updated: July 26, 2026. We notify customers 30 days before adding new sub-processors.
Documents & Resources
How we collect, use, and protect your data.
Legal terms governing use of the Kolva platform.
GDPR-compliant DPA for enterprise customers.
Information about cookies and tracking technologies.
Detailed security measures and certifications.
Uptime guarantees, response times, and remedies.
Live system status and incident history.
Incident Response
< 1 hour
Response time for critical incidents
< 4 hours
Customer notification for data incidents
5 days
Post-mortem published (business days)
We maintain a public status page with real-time uptime monitoring and incident history.
View system statusOur team is ready to help with security assessments, compliance questionnaires, or any data protection inquiries. We also welcome responsible vulnerability disclosures.
21-day free trial. No credit card required.