Security Overview
Kampra's approach to protecting customer data.
Encryption
Data in transit is encrypted using TLS. Data at rest is encrypted using industry-standard algorithms provided by our cloud infrastructure providers.
Authentication and access
Kampra supports email and Google sign-in and is designed to support multi-factor authentication and SSO for enterprise plans. Access to production systems by Kampra staff is limited to authorized personnel and logged.
Application security
Row-level security is enforced on all customer data tables. Least-privilege service roles are used for privileged operations. Inputs are validated server-side and sensitive endpoints are rate limited.
Logging and audit trails
Application and infrastructure events are logged and retained to support security investigations, in accordance with our Data Retention Policy.
Backups and disaster recovery
Kampra relies on cloud-provider backup and point-in-time recovery mechanisms. Recovery objectives are documented internally and reviewed periodically.
Incident response
Kampra maintains an incident response process for detection, containment, eradication, recovery, and post-incident review. Affected customers are notified in accordance with applicable law and the DPA.
Vendor management
Subprocessors are evaluated for security posture and bound by contractual obligations consistent with our commitments.
Compliance posture
Kampra is designed to support common enterprise control frameworks. Kampra does not currently claim SOC 2 or ISO 27001 certification. Where certifications are relevant to your procurement, contact security@trykampra.com.
Contact
Security questions: security@trykampra.com.
