Kusari helps organizations secure their software supply chains — and we hold ourselves to the same standard. Protecting the confidentiality, integrity, and availability of customer data is a commitment we make to every customer.
On this page
- Compliance
- Infrastructure
- Data protection
- Access control
- Secure development
- Monitoring and incident response
- Reporting a vulnerability
Compliance
Kusari has completed a SOC 2 Type II examination and continuously monitors its security controls against the SOC 2 Trust Services Criteria using a compliance automation platform. Customers and prospects can request security documentation at security@kusari.dev.
Infrastructure
The Kusari platform runs entirely on Amazon Web Services (AWS). We inherit the physical and environmental security of AWS data centers, and production systems are kept separate from development and testing environments. Kusari is a fully remote company.
Data protection
- Customer data is encrypted in transit using TLS and encrypted at rest.
- Customer data is logically isolated between customers.
- Customer data is retained and deleted in accordance with our Terms of Service and Privacy Policy.
Access control
- Employee access to production systems and business applications is provisioned through single sign-on with multi-factor authentication.
- Access follows least privilege: permissions are granted by role, reviewed regularly, and revoked promptly on role change or departure.
- Support access to customer data is restricted to authorized personnel, individually authorized, and logged.
- Production access is tightly restricted; elevated access is time-boxed, approved, and audited.
- Personnel complete security awareness training as part of onboarding.
Secure development
We practice what we build. Kusari's own software supply chain follows the practices our platform enables for customers:
- Changes are peer reviewed and deployed through automated pipelines.
- Dependencies are continuously monitored for known vulnerabilities.
- Infrastructure is defined as code, version controlled, and auditable.
- The platform has undergone independent penetration testing.
Monitoring and incident response
We centrally log and monitor our production environment, alert on anomalous activity, and maintain an incident response process with defined roles. Customer notification follows our contractual commitments.
Reporting a vulnerability
We welcome reports from security researchers. If you believe you've found a vulnerability in a Kusari product or service, please email security@kusari.dev with enough detail to reproduce the issue. We will acknowledge your report promptly and keep you informed as we investigate. We do not currently offer monetary rewards for vulnerability reports.
Research is in scope only for internet-facing services operated by Kusari. Do not perform denial-of-service testing, social engineering, or physical attacks; do not access, modify, or delete data that is not your own — if you encounter another user's data, stop and report it immediately; and do not degrade the service for other users. We will not pursue legal action for good-faith research conducted within these guidelines.