Security & Sovereignty

Security is the product.

Regulated industries don't adopt AI on promises. Kervalt is engineered so your data, your models, and your compliance posture stay under your control — verifiably.

Certifications & Compliance

Audited against the standards your regulators know

SOC 2

Type II

Independent, continuous audit of our security, availability, and confidentiality controls — reports available under NDA.

ISO 27001

Information Security

Certified information security management system covering every Kervalt model endpoint and the Kanda Vault platform.

ISO 42001

AI Management

Certified AI management system governing how we train, evaluate, and deploy models — accountability built into the lifecycle.

GDPR

EU Data Protection

Full GDPR alignment with EU data residency by default, documented DPAs, and data-subject rights honored across the platform.

Zero Data Retention

Your prompts are never our training data.

With Zero Data Retention (ZDR) enabled, inference requests are processed in memory and discarded the moment a response is returned. Nothing is logged, stored, or used for training — contractually guaranteed.

  • No prompt or completion persistence at any layer of the stack
  • Training on customer data is opt-in only, never default
  • ZDR status verifiable through our SOC 2 Type II audit scope
  • Configurable per workspace, enforced at the API gateway

Access Control & Isolation

Enterprise-grade controls, tenant by tenant

Role-Based Access Control

Granular RBAC with SSO and SCIM provisioning. Scope API keys, models, and spend to teams, projects, and environments — with least privilege as the default.

Single-Tenant Isolation

Dedicated compute and networking per customer in Kanda Vault. No shared inference pools, no noisy neighbors, no cross-tenant data paths.

Deploy Anywhere

Secure within your virtual private cloud (VPC), on-premises, or dedicated, Kervalt-managed Kanda Vault — the same control plane, your choice of boundary.

EU Data Residency

Data that stays in Europe, by default.

All Kervalt-managed infrastructure runs in EU regions. Inference, embeddings, and stored artifacts never leave European jurisdiction unless you explicitly deploy them elsewhere — in your own cloud, under your own residency rules.

Audit Logging

Every action, attributable.

Immutable audit trails capture authentication, key usage, model invocations, and administrative changes. Export to your SIEM in real time and hand your compliance team evidence, not assertions.

Verify it yourself.

SOC 2 Type II reports, ISO certificates, penetration-test summaries, and our data processing agreement — available to qualified teams under NDA.

Ready to deploy sovereign AI?

Run Kervalt models in your own cloud, on your own terms.

Request Demo

Ready to deploy sovereign AI?

Run Kervalt models in your own cloud, on your own terms.

Request Demo