04 · Trust & GovernanceVol. 10 · Q2 2026kleiotechnology.com

Built for thecompliance file.

Procurement, security, and audit teams are first-class citizens of every Kleio engagement. This is the documentation surface that shows up during diligence.

1 Corinthians 14:40

Let all things be done decently and in order.

§ I — Compliance

Standards we operate against.

SOC 2 Type II
In progress

Audited annually since 2021. Continuous monitoring.

ISO 27001 / 27701
In progress

Information security and privacy management systems.

HIPAA & HITRUST
In progress

BAA-ready. Production deployments since 2019.

GDPR & CCPA
In progress

Data-residency options across US, EU, UK.

FedRAMP-aligned
In progress

Reference architectures for moderate workloads.

PCI-DSS Level 1
In progress

Tokenization, vaulting and audit trail patterns.

§ II — Governance

How an engagement is run.

Architecture Review Board

Every engagement opens with a written architectural decision record. You keep the document.

Master Services Agreement

Standard MSA with named-team continuity, IP ownership, and exit clauses written in plain English.

Engagement insurance

$5M E&O · $5M Cyber · $2M General. Certificates on request.

Quarterly business review

SLO performance, spend vs. plan, risk register. Reviewed with your CFO and CTO.

§ III — Security posture

The unsexy infrastructure of trust.

Identity & access

SSO via SAML/OIDC. Hardware-backed second factor required for production. Quarterly access reviews, evidenced.

Data handling

Tenant isolation by default. Encryption at rest (AES-256) and in transit (TLS 1.3). Data residency options across US, EU, UK.

Vulnerability mgmt

Continuous SCA + SAST + DAST. Annual penetration tests by an independent firm. Patch SLAs aligned to CVSS.

Incident response

24/7 on-call. Defined severity matrix. Customer notification within 24 hours of confirmed material incident.

Vendor management

Subprocessors reviewed quarterly. Public list maintained. SCCs and DPAs available.

Business continuity

RTO 4 h, RPO 15 min for managed-platform engagements. Quarterly DR exercises.

§ IV — Documentation
SOC 2 Type II report
↓ Request access
ISO 27001 certificate
↓ Request access
Pen-test executive summary
↓ Request access
Subprocessor list
↓ Request access
DPA template
↓ Request access
Insurance certificates
↓ Request access
MSA template
↓ Request access
Architecture sample letter
↓ Request access
Season