Security & compliance
Enterprise-grade security. Your data is safe with us.
Encryption
All data is encrypted in transit with TLS 1.3, and HTTPS is enforced across the platform (HSTS). Secrets you entrust to us — AI provider keys, webhook signing secrets — are encrypted at rest with AES-256-GCM. Database encryption at rest is handled by our hosting provider.
Infrastructure
KelpFund runs on a server located in France. The database and files are stored there, and KelpFund backs them up every day.
Access control
We enforce role-based access control (RBAC) on a least-privilege basis: every member of an organisation is an Admin, Member or Viewer. Authentication events are logged. Sign-in with Google, Microsoft or GitHub is available, so your organisation's own strong-authentication policy applies.
Monitoring & incident response
Application and server errors are reported automatically to our monitoring tool. Report any incident to security@kelpfund.com — we acknowledge within 24 business hours.
Compliance & data protection
SOC 2 Type II — Controls aligned to SOC 2; independent audit in progress, not yet certified.
GDPR — EU data protection built in: consent tracking, data export, and a Data Processing Agreement.
ISO 27001 — Practices aligned to ISO 27001; certification not yet obtained.
Report a vulnerability
We take security seriously. If you discover a vulnerability, please email security@kelpfund.com. We follow coordinated disclosure and aim to acknowledge reports within 24 hours. We do not pursue legal action against researchers acting in good faith.
Need a Data Processing Agreement?
Our Data Processing Agreement is available on request. Get in touch and we will send it over.
Request our DPA