Compliance
Certifications, audit reports, and the SOC 2 program timeline.
Active certifications
None. KONDWIT holds no SOC 2 report, no ISO certification, and no other third-party security attestation. The SOC 2 program is in its readiness phase — see the timeline below for exactly where it stands.
SOC 2 program
KONDWIT is pursuing SOC 2 Type II covering Security, Availability, and Confidentiality Trust Service Criteria. The phases below are the plan; the status against each is stated as of 11 August 2026.
- Phase A — Readiness (current phase, in progress): compliance platform onboarding, policy package, control gap closure, internal readiness review. A written policy package and control matrix exist and a manual gap assessment against the live environment was completed on 11 August 2026. Still outstanding: the compliance platform is undecided, the policy package has not been formally approved (the policies carry DRAFT status), and no external readiness review has been performed.
- Phase B — Type I audit (not started): point-in-time audit; report published to this page (NDA-gated download). No auditor has been engaged and no audit is underway.
- Phase C — Type II window (not started): 6 months of continuous evidence collection.
- Phase D — Type II audit (not started): auditor reviews the window; report published.
We have not committed to dates for Phases B through D, and we will not publish any until an auditor is engaged. If a SOC 2 report is a gating requirement for your procurement today, KONDWIT does not meet it.
Future certifications
- ISO 27001: roadmap; complementary to SOC 2. No work started.
- HIPAA: engage if a customer requires. No work started.
Customer questionnaires
Pre-populated SIG and CAIQ questionnaire responses have not been produced yet — there is no completed questionnaire to release, under NDA or otherwise. If you need either, email security@kondwit.com and we will complete your copy directly against this Trust Center.