KelpFund/Security & compliance
Security

Security & compliance

Enterprise-grade security. Your data is safe with us.

Encryption

All data is encrypted in transit with TLS 1.3, and HTTPS is enforced across the platform (HSTS). Secrets you entrust to us — AI provider keys, webhook signing secrets — are encrypted at rest with AES-256-GCM. Database encryption at rest is handled by our hosting provider.

Infrastructure

KelpFund runs on a server located in France. The database and files are stored there, and KelpFund backs them up every day.

Access control

We enforce role-based access control (RBAC) on a least-privilege basis: every member of an organisation is an Admin, Member or Viewer. Authentication events are logged. Sign-in with Google, Microsoft or GitHub is available, so your organisation's own strong-authentication policy applies.

Monitoring & incident response

Application and server errors are reported automatically to our monitoring tool. Report any incident to security@kelpfund.com — we acknowledge within 24 business hours.

Compliance & data protection

SOC 2 Type II

SOC 2 Type II — Controls aligned to SOC 2; independent audit in progress, not yet certified.

GDPR

GDPR — EU data protection built in: consent tracking, data export, and a Data Processing Agreement.

ISO 27001

ISO 27001 — Practices aligned to ISO 27001; certification not yet obtained.

Report a vulnerability

We take security seriously. If you discover a vulnerability, please email security@kelpfund.com. We follow coordinated disclosure and aim to acknowledge reports within 24 hours. We do not pursue legal action against researchers acting in good faith.

Need a Data Processing Agreement?

Our Data Processing Agreement is available on request. Get in touch and we will send it over.

Request our DPA