> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kvelden.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Compliance

> SOC 2, ISO 27001, GDPR, HIPAA, and more — how Enclave supports your compliance posture.

## Compliance posture

| Framework        | Enclave status  | Notes                                   |
| ---------------- | --------------- | --------------------------------------- |
| SOC 2 Type II    | ✓ Compliant     | Report available under NDA              |
| ISO 27001        | ✓ Certified     | Certificate available on request        |
| GDPR             | ✓ Compliant     | DPA available                           |
| HIPAA            | ✓ BAA available | Business Associate Agreement on request |
| DPDP Act 2023    | ✓ Compliant     | India data residency supported          |
| IT Act 2000      | ✓ Compliant     |                                         |
| FedRAMP          | In progress     | —                                       |
| Cyber Essentials | ✓ Certified     |                                         |

## SOC 2 Type II

Enclave undergoes annual SOC 2 Type II audits covering:

* **Security** — access controls, encryption, vulnerability management
* **Availability** — uptime SLAs, incident response
* **Confidentiality** — data classification, key management

The audit report is available to prospective and current customers under NDA. Contact [hello@kvelden.com](mailto:hello@kvelden.com) to request a copy.

## GDPR

Enclave's zero-knowledge architecture directly supports GDPR obligations:

* **Data minimisation** — Kvelden processes only metadata, never plaintext content
* **Right of erasure** — deleting a room destroys the KEK, permanently rendering all files unreadable
* **Data residency** — EU-region deployments available; data does not leave your selected region
* **Sub-processors** — full list available in the DPA

A Data Processing Agreement (DPA) is available at [kvelden.com/legal/dpa](https://kvelden.com/legal/dpa).

## HIPAA

Enclave is HIPAA-eligible. For covered entities and business associates:

* AES-256-GCM encryption satisfies the HIPAA Security Rule encryption standard
* Audit logs satisfy access logging requirements (§164.312(b))
* BYOK/HYOK ensures ePHI keys are controlled by the covered entity
* A Business Associate Agreement (BAA) is available on request

## Data residency

| Region                 | Available |
| ---------------------- | --------- |
| India (Mumbai)         | ✓         |
| EU (Frankfurt)         | ✓         |
| US East (Virginia)     | ✓         |
| US West (Oregon)       | ✓         |
| Singapore              | ✓         |
| Custom (private cloud) | ✓         |

Data stored in a region never leaves that region unless explicitly exported by an administrator.

## Generating compliance reports

Enclave can generate compliance reports for internal use or auditor submission:

1. Navigate to **Reports → Compliance**
2. Select the framework (SOC 2, ISO 27001, GDPR, HIPAA, etc.)
3. Set the reporting period
4. Click **Generate** — the report is produced as a signed PDF

Reports include: access review results, permission changes, key management events, and an integrity verification of the underlying audit log.

## Penetration testing

Enclave undergoes annual penetration tests by a CREST-accredited firm. Executive summaries are available to customers under NDA. Customers may also conduct their own penetration tests against their Enclave instance — notify [security@kvelden.com](mailto:security@kvelden.com) at least 5 business days in advance.
