Building Aegis Sovereign — Our proprietary platform, actively deployed and improving daily. See the platform →
Home/Trust Center
Trust Center

Security and privacy
you can verify

Kaimz is self-hosted by default — your telemetry and data never leave your own infrastructure. Here's exactly how we protect it, what we align to, and how to reach us.

Security practices
Self-hosted, signed commands, MFA, RBAC, encryption in transit.
Data & privacy
Your data stays in your walls. We collect the minimum, sell nothing.
Compliance
Built to support SOC 2, HIPAA, PCI-DSS, ISO 27001, PIPEDA, PHIPA.
Responsible disclosure
Found a vulnerability? Here's how to report it safely.
Availability
Offline-resilient by design — no gaps in visibility during outages.
Sub-processors
Self-hosted means almost none. Full transparency on what we use.

Security practices

Kaimz is engineered so that the security tool itself isn't a new attack surface. The architecture is self-contained inside your network, and every privileged action is authenticated and signed.

Data & privacy

Because Kaimz is self-hosted, the most sensitive data — your endpoint telemetry, alerts and investigations — never leaves your environment. There's no shared multi-tenant cloud holding your security data.

Read the full Privacy Policy for how we handle contact-form and account data.

Compliance & frameworks

Kaimz is built to help you meet the controls your auditors care about — and Pro/Enterprise generate compliance evidence packs that map live platform signals (EDR coverage, MFA, logging, patch posture) to framework controls.

SOC 2HIPAAPCI-DSS v4.0 ISO 27001PIPEDAPHIPA

Honest note: "built to support / aligned to" describes how the platform helps you satisfy these frameworks. Where Kaimz Inc. itself holds a third-party certification or attestation, we'll publish the report here and on request — ask us at contact@kaimz.org.

Responsible disclosure

We welcome reports from security researchers. If you believe you've found a vulnerability in kaimz.org or the Kaimz platform, please tell us before disclosing publicly, and we'll work with you in good faith.

Availability & resilience

Security can't have blind spots during an outage. Kaimz agents persist every event to crash-safe local storage and reconcile the full timeline when connectivity returns — no gaps, no duplicates.

Sub-processors

Self-hosting means there are almost no third parties in the path of your security data. For full transparency:

Transparency is the brand. We'd rather tell you exactly how something works than hand-wave. Have a security, privacy or compliance question this page didn't answer? Email contact@kaimz.org and a human will respond.
Evaluate with confidence

See it running, on your terms

Deploy free Talk to security