Controls you can walk in 45 minutes.

Documents, claim conversations, and customer evidence need more than a perimeter. Kiso builds access, verification, and an audit trail into the work itself. We will sit with InfoSec and go through it.

One screen

What we actually control.

A concise view of Kiso’s current product controls, written in the language security and operations teams evaluate.

ControlWhat it means
Encryption in transitTraffic to Kiso is encrypted.
AuthenticationAccounts, scoped roles, secure links, optional OTP and step-up at higher-risk moments.
AuditDelivery, access, signature, status, assignment, upload, and admin events stay with the work.
File handlingShort-lived upload links, malware scanning, original preservation, controlled access to media.
TenancyOrganization A cannot read organization B’s claims or documents.
Retention / legal holdRevocable access, transcript export, and legal hold support governed operations.
Layered controls

Protect the data. Prove the action.

Each control answers a simple question: who should be able to see or do this, and what evidence should remain afterward?

01 — ACCESS

Scoped authorization

Organization, role, team, participant, and claim-level controls restrict data and actions to the people who need them.

02 — IDENTITY

Verification where it matters

Secure links, expiring access, consent steps, optional OTP, and step-up verification support higher-risk moments.

03 — EVIDENCE

Auditable events

Delivery, access, signature, status, assignment, upload, and administrative events create an operational history.

04 — FILES

Controlled file handling

Secure uploads, short-lived original links, malware scanning, document integrity checks, and separated derivatives reduce exposure.

05 — TENANCY

Organization isolation

Org A cannot read org B’s claims or documents. Tenant boundaries are part of every request path—not a slide in a pitch.

06 — RETENTION

Operational controls

Legal hold, revocable access, transcript export, and configurable workflow records support governed operations.

A reviewable posture

Bring the questionnaire. We will walk the architecture.

We’ll walk InfoSec through controls in a 45-minute review: architecture, data flow, access, communications providers, and subprocessors under NDA.

  • Architecture and data-flow walkthrough
  • Subprocessor list under NDA
  • Product-specific access and retention
  • Enterprise requirements captured in the deployment scope
Request a 45-minute review

Current controls, represented accurately. This page does not claim SOC 2, HIPAA, or another regulated-status designation unless it has been expressly documented for your agreement and deployment.

Bring your security requirements to the first conversation.