Security & compliance

Audit-ready by design

KOLX is built for organizations where every engagement has to withstand scrutiny. Here's how we protect your data and keep you compliant.

Security & compliance

Built for regulated industries

Compliance-first, not compliance-bolted-on.

SOC 2 Type II

Independently audited security controls covering availability, confidentiality, and processing integrity.

HIPAA-Ready

Built with HIPAA technical safeguards in mind. Business Associate Agreements (BAA) available on all plans.

GDPR Compliant

Data residency options, right-to-erasure support, and DPA agreements for organizations operating in the EU.

Immutable Audit Trail

Every action — profile update, approval decision, document upload — is logged with actor, timestamp, and a before/after snapshot.

Enterprise Infrastructure

Hosted on SOC 2-certified cloud infrastructure with encryption at rest (AES-256) and in transit (TLS 1.3).

99.9% Uptime SLA

Enterprise plans include an uptime SLA with automatic failover, daily backups, and disaster recovery.

SOC 2 Type IIHIPAA ReadyGDPR Compliant21 CFR Part 11 ReadyFCPA Aligned

The details

What sits behind the badges.

Encryption everywhere

Data is encrypted at rest with AES-256 and in transit with TLS 1.3. Encryption keys are managed and rotated by our infrastructure provider.

Access control & RBAC

Role-based access control governs who can see and do what. SSO and SCIM provisioning are available so access follows your identity provider.

Immutable audit logging

Every profile change, approval decision, and document action is recorded with actor, timestamp, and a before/after snapshot — and cannot be edited after the fact.

Enterprise infrastructure

Hosted on SOC 2-certified cloud infrastructure with automated daily backups, failover, and disaster recovery.

Data residency

Data residency options are available for organizations operating under EU and other regional requirements.

Subprocessors & BAAs

We maintain a current subprocessor list and offer Business Associate Agreements on all plans for HIPAA-covered workflows.

Need our SOC 2 report, subprocessor list, or a completed security questionnaire? Contact us and we’ll share what your review requires.