Snapshot 20305
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Kendis Trust Centre Security, legal, and procurement resources Everything your review teams need to evaluate Kendis, available before you ask. Read the public material below, or request access to the document library for agreements, certificates, and security documentation. Security overview Kendis is a planning layer that reads work-item data from your Jira or Azure DevOps instance and visualises it for programme and team planning. That shapes what we hold: work titles, statuses, dates, dependencies and the names and email addresses of the people using Kendis. We do not hold source code, financial data or special categories of personal data. Your data lives in the Hosting Region you choose at sign-up, the United States (AWS, Northern Virginia) or Germany (OVHcloud, Frankfurt), and does not leave it. Kendis Oy holds ISO/IEC 27001:2022 certification, and the controls that certification covers are the ones that protect your account: named individual accounts for every engineer, no shared credentials, multi-factor authentication on production, all administrative access logged, and production access limited to a small team in Finland. Data is encrypted in transit and at rest. If something goes wrong we notify you within 72 hours, and when you leave you can take a full copy of your data with you. The full overview below covers architecture, access control, encryption, backups, incident response and how we handle the connection to your ALM tool. Read the full overview Last updated September 29, 2026 Security overview Connecting Kendis to your Jira or Azure DevOps means trusting us with your roadmap: what your teams are building, what's late, and what depends on what. We treat that as the most sensitive thing we hold, and the controls on this page exist for that reason. It explains what we do to protect it, in enough detail that you can check. Certifications Kendis Oy holds ISO/IEC 27001:2022, certificate 123131, covering the systems that run and support the cloud service. Our infrastructure providers hold their own SOC 2 and ISO reports, which we pass on. Sub-processors Two Hosting Regions, each with its own short list. United States: Amazon Web Services and MongoDB Atlas, both in the US. Germany: OVHcloud in Frankfurt, with bunny.net and Scaleway in the EEA for content delivery and email. No other third party has access to your data. Every addition gets 30 days' notice and a right to object, and the change log on the page is the contractual record. Legal entity You contract with Kendis Oy, a Finnish company based in Helsinki, Business ID 2874062-5, ISO 27001 certified. US customers who prefer a US counterparty can contract with Kendis US, Inc., a Delaware corporation and wholly owned subsidiary. The same service, the same DPA and the same Hosting Regions apply whichever entity signs. Registered addresses and signatory details are on the page. FAQ The questions that come up in nearly every security review, answered in plain text. Where the data is hosted and who can access it. How production access and encryption work. What happens to your data when the contract ends. Whether Kendis uses your data for AI. Each answer says whether it covers cloud, self-hosted or both, and is written so you can paste it straight into your review Document library Everything a reviewer usually asks for in one place: the licence agreements, the DPA, the Hosting and Subprocessor Schedule, the ISO 27001 certificate and the security documentation set. Verified work email gets you into most of it. The most sensitive documents, such as the penetration test summary and architecture detail, sit behind a short mutual NDA you can sign online. Open the document libraryRequest access