You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: src/content/docs/trust-center/privacy-and-compliance/compliance.mdx
+26-9Lines changed: 26 additions & 9 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -24,22 +24,24 @@ keywords:
24
24
- "SOC 2"
25
25
- "GDPR"
26
26
- "HIPAA"
27
+
- "CCPA"
28
+
- "CPRA"
27
29
- "CAIQ"
28
30
- "MVSP"
29
31
- "PCI-DSS"
30
32
- "certification"
31
33
- "security"
32
-
updated: "2025-01-27"
34
+
updated: "2025-08-26"
33
35
featured: false
34
36
deprecated: false
35
-
ai_summary: "Overview of Kinde's compliance certifications and security frameworks including ISO 27001, SOC 2 Type 2, GDPR, HIPAA, CAIQ, MVSP, and PCI-DSS compliance status."
37
+
ai_summary: "Overview of Kinde's compliance certifications and security frameworks including ISO 27001, SOC 2 Type 2, GDPR, HIPAA, CCPA, CPRA, CAIQ, MVSP, and PCI-DSS compliance status."
36
38
---
37
39
38
40
Kinde takes data privacy and security very seriously. We want you to trust us and our systems, which is why we engaged in external certification audits and conducted self assessments against globally recognized privacy and security frameworks to ensure our technology infrastructure and your data are kept secure.
39
41
40
42
## **ISO 27001**
41
43
42
-

44
+

43
45
44
46
Kinde is [ISO 27001:2022](https://www.iso.org/standard/27001) certified by [Compass Assurance Services](https://cas.com.au/) and maintains an information security management system (ISMS) with a dedicated internal security team. Our public listing is available on the [JASANZ certified organizations register](https://register.jasanz.org/certificate-details/0/af0526d5-c2d8-ed11-a7c7-00224818a490) and the [IAF CertSearch register](https://www.iafcertsearch.org/certified-entity/WrSSvBtTuGl9ks9O9oyp30SO).
45
47
@@ -49,7 +51,7 @@ ISO 27001 specifies the requirements for establishing, implementing, maintaining
49
51
50
52
## SOC 2 Type 2
51
53
52
-

54
+

53
55
54
56
Kinde has completed a SOC 2 Type 2 with report and attestation from [AssuranceLab](https://www.assurancelab.cpa/).
55
57
@@ -61,7 +63,7 @@ A [SOC 2 examination](https://www.aicpa-cima.com/topic/audit-assurance/audit-and
Kinde is compliant with the GDPR and supports our customers by maintaining strict privacy principles as a Data Processor.
67
69
@@ -71,34 +73,49 @@ More information about the GDPR and what Kinde does for comply with it can be fo
71
73
72
74
## HIPAA
73
75
74
-

76
+

75
77
76
78
Kinde is HIPAA compliant and supports our customers as a Business Associate. Reach out to our team if you need a Business Associate Agreement in place before working with us.
77
79
78
80
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a US federal law on how to protect sensitive health information, known as Protected Health Information (PHI), which led to the creation of the Privacy Rule and Security Rule. It has since been updated with additional rules and supplemented by the Health Information Technology for Economic and Clinical Health (HITECH) Act in 2009.
79
81
82
+
More information about HIPAA can be found on the US Department of Health and Human Services's [health information privacy](https://www.hhs.gov/hipaa/index.html) page.
83
+
84
+
## CCPA and CPRA
85
+
86
+

87
+
88
+
Kinde is compliant with the CCPA (as amended by the CPRA) and supports our customers by maintaining strict privacy principles.
89
+
90
+
The California Consumer Privacy Act (CCPA) gives consumers more control over the personal information that companies collect about them. The law took effect on January 1, 2020 (its initial regulations were approved on August 14, 2020) and applies to companies targeting or collecting data related to California residents. An amendment—the California Privacy Rights Act (CPRA)—expanded the CCPA’s scope; it became legally effective on December 16, 2020, most substantive provisions became operative on January 1, 2023 (with a look-back to data collected on or after January 1, 2022), and formal enforcement began July 1, 2023.
91
+
92
+
More information can be found on the California Attorney General’s [CCPA/CPRA page](https://oag.ca.gov/privacy/ccpa) and the California Privacy Protection Agency’s website.
Kinde has completed a [Consensus Assessments Initiative Questionnaire (CAIQ)](https://cloudsecurityalliance.org/star/registry/kinde/services/kinde/) from the Cloud Security Alliance and submitted to their public STAR registry as a Level 1 self-assessment.
85
98
86
99
Founded in 2013 by the Cloud Security Alliance, the Security Trust Assurance and Risk (STAR) registry encompasses key principles of transparency, rigorous auditing, and cloud security and privacy best practices.
Kinde has completed a Minimum Viable Secure Product (MVSP) self-assessment and implemented all recommended controls. Reach out to our team if you need to review our responses or have questions about specific controls.
93
106
94
107
MVSP is a list of essential application security controls that should be implemented in enterprise-ready products and services. The controls are designed to be simple to implement and provide a good foundation for building secure and resilient systems and services.
95
108
109
+
More information about MVSP can be found at the [Minimum Viable Secure Product](https://mvsp.dev/) website.
Please note that Kinde does not hold a PCI-DSS Report on Compliance (ROC) from a Qualified Security Assessor (QSA).
101
116
102
117
In preparation for Kinde’s upcoming customer billing feature, we have engaged with a QSA to validate our scoping and we are preparing the necessary Self Assessment Questionnaire (SAQ) to meet the PCI-DSS requirements for processing cardholder data. Currently we use a third party service provider and their SAQ-A scoped method, which greatly reduces the scope that Kinde has to meet as a PCI-DSS Service Provider.
103
118
104
119
Our SAQ and Attestation of Compliance (AOC) will be available when scoping work is completed and will transition to a Level 1 Service Provider when the necessary transaction volume is reached.
120
+
121
+
More information about PCI can be found at the [PCI Security Standards Council](https://www.pcisecuritystandards.org/) website.
0 commit comments