Security at Krauvix
Your procurement data is sensitive. Here is exactly how we protect it.
AES-256 EncryptionTLS 1.3 in TransitSOC 2 In ProgressGDPR Compliant
Infrastructure
Hosting
Deployed on Vercel Edge Network with Supabase (AWS us-east-1). 99.9% uptime SLA.
Data Encryption at Rest
All data encrypted with AES-256. Database encryption enabled at the storage layer.
Data Encryption in Transit
All connections enforced over TLS 1.3. HTTP traffic is redirected to HTTPS automatically.
Backups
Automated daily backups with 30-day retention. Point-in-time recovery available on Enterprise plan.
CDN
Static assets served from Vercel's global edge network across 40+ regions.
DDoS Protection
Cloudflare-backed DDoS mitigation and rate limiting on all API endpoints.
Access Controls
- Multi-factor authentication (TOTP) available for all users
- Role-based access control (RBAC) with granular permissions
- Session management: automatic logout after inactivity
- Admin audit log: every login, data export, and settings change is logged with IP and timestamp
- Row-level company isolation: your data is never accessible to other tenants
Compliance
- SOC 2 Type II: Audit in progress. Target completion: Q4 2026. Contact us for our current security questionnaire responses.
- GDPR: Krauvix acts as a Data Processor. DPA available on request. Data subject rights (access, deletion, portability) supported.
- CCPA: California consumer privacy rights honored. See our Privacy Policy.
- Data Residency: Data stored in AWS us-east-1 (N. Virginia). EU data residency available on Enterprise plan (roadmap Q1 2027).
Vulnerability Management
- We conduct regular dependency audits and apply security patches within 48 hours of disclosure.
- Responsible disclosure: security@krauvix.com. We respond within 24 hours.
- No third-party code execution in your tenant environment.
Employee Access
- Production database access is restricted to the founder, protected by MFA.
- No one at Krauvix can read your data without explicit written consent from your account admin.
- Security training is completed annually as the team grows, and every new hire signs an NDA before any data access.
Have specific security requirements?
Request our Security Questionnaire or contact security@krauvix.com