> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kvelden.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Compliance

> How Enclave supports your compliance posture — aligned to SOC 2 and ISO 27001, with GDPR, HIPAA, and DPDP support.

## Compliance posture

<Note>
  Kvelden operates Enclave against the SOC 2 Type II and ISO 27001 control
  frameworks. Formal third-party certification is in progress — we do not claim
  certifications we do not yet hold. Our current control documentation and
  attestation status are available to prospective and current customers under NDA.
</Note>

| Framework        | Enclave status | Notes                                                                    |
| ---------------- | -------------- | ------------------------------------------------------------------------ |
| SOC 2 Type II    | Aligned        | Controls mapped to the Trust Services Criteria; formal audit in progress |
| ISO 27001        | Aligned        | ISMS aligned to ISO 27001; certification in progress                     |
| GDPR             | Aligned        | DPA available                                                            |
| HIPAA            | Aligned        | Business Associate Agreement (BAA) available on request                  |
| DPDP Act 2023    | Aligned        | India data residency supported                                           |
| IT Act 2000      | Aligned        |                                                                          |
| Cyber Essentials | Aligned        | Certification in progress                                                |

## SOC 2 Type II

Enclave's controls are built and operated to the SOC 2 Type II Trust Services Criteria, covering:

* **Security** — access controls, encryption, vulnerability management
* **Availability** — uptime SLAs, incident response
* **Confidentiality** — data classification, key management

A formal SOC 2 Type II audit is in progress. Our current control documentation and attestation status are available to prospective and current customers under NDA. Contact [hello@kvelden.com](mailto:hello@kvelden.com) to request them.

## GDPR

Enclave's zero-knowledge architecture directly supports GDPR obligations:

* **Data minimisation** — Kvelden processes only metadata, never plaintext content
* **Right of erasure** — deleting a room destroys the KEK, permanently rendering all files unreadable
* **Data residency** — EU-region deployments available; data does not leave your selected region
* **Sub-processors** — full list available in the DPA

A Data Processing Agreement (DPA) is available at [kvelden.com/legal/dpa](https://kvelden.com/legal/dpa).

## HIPAA

Enclave is HIPAA-eligible. For covered entities and business associates:

* AES-256-GCM encryption satisfies the HIPAA Security Rule encryption standard
* Audit logs satisfy access logging requirements (§164.312(b))
* BYOK/HYOK ensures ePHI keys are controlled by the covered entity
* A Business Associate Agreement (BAA) is available on request

## Data residency

| Region                        | Available |
| ----------------------------- | --------- |
| India (Mumbai)                | ✓         |
| EU (Frankfurt)                | ✓         |
| US East (Virginia)            | ✓         |
| US West (Oregon)              | ✓         |
| Singapore                     | ✓         |
| Custom (on-premise appliance) | ✓         |

Data stored in a region never leaves that region unless explicitly exported by an administrator.

## Generating compliance reports

Enclave can generate compliance reports for internal use or auditor submission:

1. Navigate to **Reports → Compliance**
2. Select the framework (SOC 2, ISO 27001, GDPR, HIPAA, etc.)
3. Set the reporting period
4. Click **Generate** — the report is produced as a signed PDF

Reports include: access review results, permission changes, key management events, and an integrity verification of the underlying audit log.

## Penetration testing

Enclave is penetration tested by an independent CREST-accredited firm; executive summaries are available to customers under NDA. Customers may also conduct their own penetration tests against their Enclave instance — notify [security@kvelden.com](mailto:security@kvelden.com) at least 5 business days in advance.
