Security, compliance, and data protection at Kolva. Everything you need to evaluate our platform for your organization.
Security and control
Your ERP data remains governed by your organization. Kolva applies controlled access, human validation, and revocable permissions across the intelligence layer.
ERP agents use read-only source access unless a separately scoped action is explicitly enabled.
Transport and storage protections cover data moving through Kolva and data persisted by the platform.
User, role, company, and data scopes determine which context and actions are available.
Discovery workflows minimize and sanitize technical metadata before support analysis.
Support interventions follow a controlled workflow with actor, scope, and timing context.
Permission-gated actions inside Kolva require explicit authorization and human validation. The standard ERP synchronization path remains outbound and read-only.
Customers retain control over connector, user, token, and assistant access revocation.
Compliance Status
Type I planned — Type II to follow. Service Organization Control audit covering security, availability and confidentiality. No engagement letter has been published yet.
Full compliance with the EU General Data Protection Regulation. DPA available for all customers.
California Consumer Privacy Act compliance. Data access, deletion, and opt-out rights fully supported.
Information security management system certification. On the roadmap for 2027.
The Kolva platform (ERP intelligence) is not a HIPAA covered entity or business associate. The separate Vera Bio clinical product (kolva.health) processes health data under its own compliance posture.
Data Handling
Primary region: EU (AWS eu-west-1, Ireland). Any alternate residency requirement is reviewed contractually before rollout.
Encryption at rest is provided by our hosting providers (Supabase on AWS: AES-256). Transport uses TLS 1.2 or higher, TLS 1.3 where the client supports it. ERP credentials are sealed with cloud KMS envelope encryption (AES-256-GCM).
Customer data is retained for the subscription term. Deletion within 30 days of a verified request; GDPR export on request. Per-company retention settings are on the roadmap.
Database backups are managed by the hosting provider (Supabase). Point-in-time recovery and backup retention depend on the subscribed plan; evidence is available to customers on request.
ERP agents run on your corporate network. Data stays local until synced over HTTPS. No inbound ports required.
The standard ERP synchronization path is outbound-only and requires no inbound ports. Separately enabled sensitive actions use explicit, permission-gated workflows outside this default read path.
Sub-processors
| Provider | Purpose | Location | Compliance |
|---|---|---|---|
| Supabase | Database & Authentication | AWS EU (Ireland) | SOC 2 |
| Vercel | Hosting & CDN | Global Edge | SOC 2 |
| Stripe | Payment Processing | US / EU | PCI DSS Level 1 |
| Resend | Transactional Email | US | SOC 2 |
| Anthropic | AI Processing (Claude) | US | SOC 2 |
| OpenAI | AI language models, speech processing and embeddings | US | SOC 2 |
| Inngest | Task Orchestration | US | SOC 2 |
| Upstash | Rate Limiting & Caching | Global | SOC 2 |
| Google Cloud KMS | Envelope encryption of ERP credentials | EU | SOC 2 |
| AWS KMS | Legacy envelope-encryption keys (read-only) | EU | SOC 2 |
| ElevenLabs | Text-to-speech (Académie, Finance voice answers) | US | SOC 2 |
| Sentry | Error and performance monitoring (PII scrubbed) | US | SOC 2 |
| Google Maps Platform | Geocoding of customer addresses | Global | ISO 27001 |
Last updated: August 22, 2026. We notify customers 30 days before adding new sub-processors.
Documents & Resources
How we collect, use, and protect your data.
Legal terms governing use of the Kolva platform.
GDPR-compliant DPA for enterprise customers.
Information about cookies and tracking technologies.
Detailed security measures and certifications.
Uptime guarantees, response times, and remedies.
Live system status and incident history.
Incident Response
From 15 min
Response time for critical incidents (P1, Enterprise SLA)
≤ 48 h
Customer notification for personal data breaches (DPA)
≤ 10
Post-incident summary for P1 incidents (business days)
We publish a service status page. Live uptime monitoring integration is in progress.
View system statusOur team is ready to help with security assessments, compliance questionnaires, or any data protection inquiries. We also welcome responsible vulnerability disclosures.
21-day free trial. No credit card required.