Security

Enterprise security.
Independently verified.

ISO 27001 certified. Annual third-party penetration testing. SSO via Entra, Okta, and Google. TLS everywhere. NZ Government Cloud Framework assessed. Your data, protected.

Platform Security

Koordinates security posture

🛡

ISO 27001

Certified information security management system. Independently audited annually by a third-party assessor.

🔐

SSO & Identity

Entra ID (Azure AD), Okta, Google. SAML and OIDC protocols. Enforce MFA across your organisation.

🔒

Encryption

TLS 1.2+ in transit. AES-256 at rest. All data encrypted by default, no opt-in required.

🧪

Penetration Testing

Annual third-party penetration testing. OWASP Top 10 validated. Results available under NDA.

🏛

NZ Cloud Framework

Assessed against the NZ Government Cloud Framework. Suitable for government workloads and classified data.

📋

Access Controls

Fine-grained permissions. Groups, roles, dataset-level and service-level controls. Full audit trail on every action.

KxAI Security

AI governance is security

When AI agents access your data, the same security principles apply — identity, authorization, audit, and revocation. KxAI adds these controls natively.

Data Sovereignty

Platform data stays in Koordinates cloud with NZ residency. KxAI on-prem licence runs data and AI governance inside your perimeter — indexing internal sources without moving data.

AI Audit Trail

Every AI query logged with agent identity, timestamp, dataset accessed, and results returned.

Token Lifecycle

Issue, rotate, and revoke API tokens for AI agents. Scoped permissions per token.

Allowlist-Only

No AI agent accesses your data unless explicitly allowed. Default deny. Policy per dataset.

For Procurement Teams

Pre-answered security questionnaire

We know you have a security review process. Here's a head start on the common questions. Full details available under NDA.

  • ISO 27001 certified — certificate available on request
  • Annual third-party penetration test — report under NDA
  • Data encrypted at rest (AES-256) and in transit (TLS 1.2+)
  • SSO via SAML/OIDC — Entra, Okta, Google supported
  • RBAC with dataset-level and service-level granularity
  • Full audit trail — exportable, searchable, immutable
  • NZ Government Cloud Framework assessed
  • KxAI on-prem licence available — data indexing and AI governance inside your network
  • Incident response plan — documented and tested
  • Business continuity — RTO < 4h, RPO < 1h
Compliance Standards

What we're assessed against

ISO

ISO/IEC 27001:2022

Information security management system

NZ

NZ Government Cloud Framework

Risk assessment for government workloads

OWASP

OWASP Top 10

Web application security validated annually

Need the full
security package?

Request our security documentation pack — ISO certificate, pen test summary, architecture overview, and compliance matrix.

Request security review →