Last updated: July 26, 2026

Trust Center

Security, compliance, and data protection at Kolva. Everything you need to evaluate our platform for your organization.

Security and control

Enterprise intelligence without losing control

Your ERP data remains governed by your organization. Kolva applies controlled access, human validation, and revocable permissions across the intelligence layer.

Read-only ERP access by default

ERP agents use read-only source access unless a separately scoped action is explicitly enabled.

Encryption in transit and at rest

Transport and storage protections cover data moving through Kolva and data persisted by the platform.

Scoped permissions

User, role, company, and data scopes determine which context and actions are available.

Sanitized discovery data

Discovery workflows minimize and sanitize technical metadata before support analysis.

Traceable support actions

Support interventions follow a controlled workflow with actor, scope, and timing context.

Human validation for sensitive actions

Permission-gated actions inside Kolva require explicit authorization and human validation. The standard ERP synchronization path remains outbound and read-only.

Customer-controlled revocation

Customers retain control over connector, user, token, and assistant access revocation.

View full security details

Compliance Status

Certifications and regulatory compliance

SOC 2 Type I

Planned

Type I planned — Type II to follow. Service Organization Control audit covering security, availability and confidentiality. No engagement letter has been published yet.

GDPR

Compliant

Full compliance with the EU General Data Protection Regulation. DPA available for all customers.

CCPA

Compliant

California Consumer Privacy Act compliance. Data access, deletion, and opt-out rights fully supported.

ISO 27001

Planned

Information security management system certification. On the roadmap for 2027.

HIPAA

Not applicable

The Kolva platform (ERP intelligence) is not a HIPAA covered entity or business associate. The separate Vera Bio clinical product (kolva.health) processes health data under its own compliance posture.

Download Data Processing Agreement

Data Handling

How we handle your data

Data Residency

Primary region: EU (AWS eu-west-1, Ireland). Any alternate residency requirement is reviewed contractually before rollout.

Data Encryption

Encryption at rest is provided by our hosting providers (Supabase on AWS: AES-256). Transport uses TLS 1.2 or higher, TLS 1.3 where the client supports it. ERP credentials are sealed with cloud KMS envelope encryption (AES-256-GCM).

Data Retention

Customer data is retained for the subscription term. Deletion within 30 days of a verified request; GDPR export on request. Per-company retention settings are on the roadmap.

Backups

Database backups are managed by the hosting provider (Supabase). Point-in-time recovery and backup retention depend on the subscribed plan; evidence is available to customers on request.

On-Premise Option

ERP agents run on your corporate network. Data stays local until synced over HTTPS. No inbound ports required.

On-Premise Agent Data Flow

Your network
ERP System
Sage X3 / SAP
SELECT / GET only
Your network
Kolva Agent
Node.js service
HTTPS POST
EU (Ireland)
Kolva Cloud
PostgreSQL / AES-256

The standard ERP synchronization path is outbound-only and requires no inbound ports. Separately enabled sensitive actions use explicit, permission-gated workflows outside this default read path.

Sub-processors

Third-party service providers

Kolva sub-processors, purposes, locations, and compliance
ProviderPurposeLocationCompliance
SupabaseDatabase & AuthenticationAWS EU (Ireland)SOC 2
VercelHosting & CDNGlobal EdgeSOC 2
StripePayment ProcessingUS / EUPCI DSS Level 1
ResendTransactional EmailUSSOC 2
AnthropicAI Processing (Claude)USSOC 2
OpenAIAI language models, speech processing and embeddingsUSSOC 2
InngestTask OrchestrationUSSOC 2
UpstashRate Limiting & CachingGlobalSOC 2
Google Cloud KMSEnvelope encryption of ERP credentialsEUSOC 2
AWS KMSLegacy envelope-encryption keys (read-only)EUSOC 2
ElevenLabsText-to-speech (Académie, Finance voice answers)USSOC 2
SentryError and performance monitoring (PII scrubbed)USSOC 2
Google Maps PlatformGeocoding of customer addressesGlobalISO 27001

Last updated: August 22, 2026. We notify customers 30 days before adding new sub-processors.

Documents & Resources

Legal and security documentation

Incident Response

Our commitment when things go wrong

From 15 min

Response time for critical incidents (P1, Enterprise SLA)

≤ 48 h

Customer notification for personal data breaches (DPA)

≤ 10

Post-incident summary for P1 incidents (business days)

We publish a service status page. Live uptime monitoring integration is in progress.

View system status

Questions about security or compliance?

Our team is ready to help with security assessments, compliance questionnaires, or any data protection inquiries. We also welcome responsible vulnerability disclosures.

Ready to get started?

21-day free trial. No credit card required.