Enterprise security.
Independently verified.
ISO 27001 certified. Annual third-party penetration testing. SSO via Entra, Okta, and Google. TLS everywhere. NZ Government Cloud Framework assessed. Your data, protected.
Koordinates security posture
ISO 27001
Certified information security management system. Independently audited annually by a third-party assessor.
SSO & Identity
Entra ID (Azure AD), Okta, Google. SAML and OIDC protocols. Enforce MFA across your organisation.
Encryption
TLS 1.2+ in transit. AES-256 at rest. All data encrypted by default, no opt-in required.
Penetration Testing
Annual third-party penetration testing. OWASP Top 10 validated. Results available under NDA.
NZ Cloud Framework
Assessed against the NZ Government Cloud Framework. Suitable for government workloads and classified data.
Access Controls
Fine-grained permissions. Groups, roles, dataset-level and service-level controls. Full audit trail on every action.
AI governance is security
When AI agents access your data, the same security principles apply — identity, authorization, audit, and revocation. KxAI adds these controls natively.
Data Sovereignty
Platform data stays in Koordinates cloud with NZ residency. KxAI on-prem licence runs data and AI governance inside your perimeter — indexing internal sources without moving data.
AI Audit Trail
Every AI query logged with agent identity, timestamp, dataset accessed, and results returned.
Token Lifecycle
Issue, rotate, and revoke API tokens for AI agents. Scoped permissions per token.
Allowlist-Only
No AI agent accesses your data unless explicitly allowed. Default deny. Policy per dataset.
Pre-answered security questionnaire
We know you have a security review process. Here's a head start on the common questions. Full details available under NDA.
- ✅ ISO 27001 certified — certificate available on request
- ✅ Annual third-party penetration test — report under NDA
- ✅ Data encrypted at rest (AES-256) and in transit (TLS 1.2+)
- ✅ SSO via SAML/OIDC — Entra, Okta, Google supported
- ✅ RBAC with dataset-level and service-level granularity
- ✅ Full audit trail — exportable, searchable, immutable
- ✅ NZ Government Cloud Framework assessed
- ✅ KxAI on-prem licence available — data indexing and AI governance inside your network
- ✅ Incident response plan — documented and tested
- ✅ Business continuity — RTO < 4h, RPO < 1h
What we're assessed against
ISO/IEC 27001:2022
Information security management system
NZ Government Cloud Framework
Risk assessment for government workloads
OWASP Top 10
Web application security validated annually
Need the full
security package?
Request our security documentation pack — ISO certificate, pen test summary, architecture overview, and compliance matrix.
Request security review →