Security & Trust.

Kraken OS runs on the data that runs your operation. We treat its security as a fundamental requirement and build protection into every layer of the platform.

Certifications & standards

The platform is built to meet rigorous industry standards and undergoes independent auditing to keep your data safe.

SOC 2 Type IIn progress

Independent audit of the design of our security controls at a point in time.

SOC 2 Type IIIn progress

Independent audit of the operating effectiveness of our controls over an extended period.

ISO 27001In progress

International standard for information security management systems.

How we protect your data

Data Protection

Encryption
  • ·AES-256 encryption at rest for all stored data
  • ·TLS 1.3 enforced for all data in transit
  • ·Secrets management with automatic rotation
  • ·Logical isolation of each facility's operational data

Identity & Access Controls

Access
  • ·Role-based access control with least privilege
  • ·SSO via trusted identity providers
  • ·Session management with configurable timeout policies
  • ·Scoped service credentials for system-to-system calls

Platform Security

Infrastructure
  • ·Isolated cloud infrastructure per environment
  • ·Automated vulnerability scanning and dependency auditing
  • ·DDoS protection and WAF at the edge layer
  • ·Signed webhooks and JWT-based service authentication

Security Operations

Operations
  • ·Continuous security monitoring and incident response
  • ·Audit logs for sensitive platform operations
  • ·Third-party penetration testing
  • ·Responsible disclosure program for security researchers

Report a vulnerability

If you believe you have found a security vulnerability in Kraken OS, please report it responsibly to [email protected]. We investigate all reports and aim to respond within 48 hours.