klink.cloud Trust Center Request access

klink.cloud

klink.cloud is the omnichannel customer engagement platform that unifies calls, chat, email and social messaging into one inbox, with AI agents, workflow automation and telephony built in.

Controls

Updated just nowSynced automatically from our cloud infrastructure. Controls are reviewed on our ISO/IEC 27001 audit cycle.

These are the controls we operate under our ISO/IEC 27001 information security management system. Each is reviewed as part of the annual audit cycle.

Infrastructure security

ControlStatus
Production hosted on AWS

The platform runs on Amazon Web Services in the region the customer selects, so data residency is a deployment choice rather than a support ticket.

Operating
Data encrypted in transit

Traffic between customers, agents and the platform is carried over TLS 1.2 or higher.

Operating
Data encrypted at rest

Stored data, including recordings and transcripts, is encrypted with AES-256.

Operating
Encryption key access restricted

Privileged access to encryption keys is limited to named operators with a business need.

Operating
Network access controlled

Production runs in private subnets with security groups restricting inbound access to what each tier requires.

Operating
Infrastructure defined in version control

Infrastructure changes are applied through reviewed configuration rather than by hand on a console.

Operating
Multi-factor authentication on production

Access to production infrastructure requires a second factor in addition to a password.

Operating
Continuous monitoring and alerting

Infrastructure health and availability are monitored, with alerts routed to an on-call owner.

Operating

Product security

ControlStatus
Single sign on available

Enterprise customers can authenticate their agents through their own identity provider.

Operating
Role based access control

Every tenant assigns permissions by role, so an agent sees only the queues and records their role allows.

Operating
Tenant data logically separated

Each tenant's data is separated so that one customer cannot address another customer's records.

Operating
Audit logging of administrative actions

Administrative changes are recorded on a timeline a customer can review.

Operating
Penetration testing performed

An independent third party tests the platform, and findings are tracked to remediation.

Operating
Dependencies scanned for vulnerabilities

Third party packages are scanned against known vulnerability databases.

Operating
Code peer reviewed before release

Changes reach production through review by an engineer other than the author.

Operating
Private cloud and on-premise deployment

Customers with stricter requirements can run the platform in an environment they control.

Operating

Organizational security

ControlStatus
Security policies reviewed annually

The policy set governing the ISMS is reviewed and approved at least once a year.

Operating
Security awareness training

Staff complete security training when they join and each year after.

Operating
Background checks performed

Checks are carried out on hire where local law permits.

Operating
Confidentiality agreements signed

Staff and contractors sign confidentiality agreements before handling customer data.

Operating
Code of conduct acknowledged

Staff and contractors acknowledge the code of conduct.

Operating
Access reviewed and revoked

Access is reviewed on role change and revoked on departure.

Operating
Asset inventory maintained

Company assets are inventoried, and disposal is documented.

Operating

Internal security procedures

ControlStatus
Incident response plan established

A documented plan covers detection, triage, escalation and customer notification.

Operating
Continuity and recovery plans tested

Business continuity and disaster recovery plans are exercised and the result recorded.

Operating
Risk assessments performed

Risks to the ISMS are assessed at least annually and treated.

Operating
Vendors assessed before onboarding

Suppliers with access to data are assessed before engagement and reviewed periodically.

Operating
Backups taken and restoration tested

Backups are taken on a schedule, and restoration is tested rather than assumed.

Operating
Change management followed

Production releases follow a documented change process.

Operating
Internal audit performed

The ISMS is audited internally against the standard.

Operating

AI and model providers

ControlStatus
Model providers listed as sub-processors

Every model provider with access to conversation content is published in the sub-processor list.

Operating
Customer data not used for model training

Data sent through the providers' business APIs is excluded from model training under their published terms.

Operating
AI features are opt in per tenant

A tenant that has not enabled Kai sends no conversation content to a model provider.

Operating
Only the content needed is sent

The request sent to a model carries the conversation content required to answer it and the knowledge base the customer published, not the whole account.

Operating
Model output reviewed before action

Kai escalates to a human rather than acting where a configured confidence threshold is not met.

Operating
Private deployment avoids third party models

Customers who cannot send data to an external model provider can run a private deployment.

Operating

Data residency

ControlStatus
Region chosen by the customer

Customer data is held in the region selected at onboarding rather than a single global location.

Operating
EU hosting on a European provider

Customers requiring EU residency are hosted on OVHcloud, under European jurisdiction.

Operating
United States region available

US customers are hosted in AWS US regions, and their data remains in the United States.

Operating
Singapore region available

Customers requiring data to stay in Singapore can be hosted there.

Operating
Cross-border transfers documented

Transfers outside the region of collection are covered by the data processing agreement, including standard contractual clauses where they apply.

Operating
Private cloud and on-premise deployment

The platform can run inside infrastructure the customer controls, so regulated data never leaves it.

Operating

Data and privacy

ControlStatus
Data classification policy established

Data is classified so that handling requirements follow its sensitivity.

Operating
Data retention periods defined

Each class of data has a defined retention period rather than being kept indefinitely.

Operating
Customer data deleted on request

Data is deleted on request and at contract end, following the published instructions.

Operating
Data processing agreement offered

A DPA covering processor obligations is available to every customer.

Operating
Sub-processors published

Parties with access to customer data are listed publicly and kept current.

Operating
Data subject requests handled

Access, correction and erasure requests are handled within statutory deadlines.

Operating