Security & Sovereignty
Security is the product.
Regulated industries don't adopt AI on promises. Kervalt is engineered so your data, your models, and your compliance posture stay under your control — verifiably.
Certifications & Compliance
Audited against the standards your regulators know
SOC 2
Type II
Independent, continuous audit of our security, availability, and confidentiality controls — reports available under NDA.
ISO 27001
Information Security
Certified information security management system covering every Kervalt model endpoint and the Kanda Vault platform.
ISO 42001
AI Management
Certified AI management system governing how we train, evaluate, and deploy models — accountability built into the lifecycle.
GDPR
EU Data Protection
Full GDPR alignment with EU data residency by default, documented DPAs, and data-subject rights honored across the platform.
Zero Data Retention
Your prompts are never our training data.
With Zero Data Retention (ZDR) enabled, inference requests are processed in memory and discarded the moment a response is returned. Nothing is logged, stored, or used for training — contractually guaranteed.
- No prompt or completion persistence at any layer of the stack
- Training on customer data is opt-in only, never default
- ZDR status verifiable through our SOC 2 Type II audit scope
- Configurable per workspace, enforced at the API gateway
Access Control & Isolation
Enterprise-grade controls, tenant by tenant
Role-Based Access Control
Granular RBAC with SSO and SCIM provisioning. Scope API keys, models, and spend to teams, projects, and environments — with least privilege as the default.
Single-Tenant Isolation
Dedicated compute and networking per customer in Kanda Vault. No shared inference pools, no noisy neighbors, no cross-tenant data paths.
Deploy Anywhere
Secure within your virtual private cloud (VPC), on-premises, or dedicated, Kervalt-managed Kanda Vault — the same control plane, your choice of boundary.
EU Data Residency
Data that stays in Europe, by default.
All Kervalt-managed infrastructure runs in EU regions. Inference, embeddings, and stored artifacts never leave European jurisdiction unless you explicitly deploy them elsewhere — in your own cloud, under your own residency rules.
Audit Logging
Every action, attributable.
Immutable audit trails capture authentication, key usage, model invocations, and administrative changes. Export to your SIEM in real time and hand your compliance team evidence, not assertions.
Verify it yourself.
SOC 2 Type II reports, ISO certificates, penetration-test summaries, and our data processing agreement — available to qualified teams under NDA.
Ready to deploy sovereign AI?
Run Kervalt models in your own cloud, on your own terms.