Snapshot 20335
Normalized text
Scripts and page chrome removed; this is what change detection compares.
// security & trust Evidence you can review. Controls you can verify. Kotav Labs delivers authorised security assessments through a controlled engagement model. This page states what we protect, how delivery is governed and where our boundaries are. Request the security pack Responsible disclosure KOTAV / TRUST CENTER Authorised testing EU-hosted evidence Reviewed delivery Tenant separation // operating safeguards Security built into the delivery model. They apply from written authorisation through to reviewed evidence and traceable delivery. 01 Authorised testing Testing starts only after scope, hosts, dates, rate limits, write permissions and Rules of Engagement are documented. 02 EU-hosted evidence Assessment infrastructure and evidence are hosted in Germany. Subprocessors and any additional processing locations are disclosed per engagement. 03 Reviewed delivery Material findings receive specialist review. Deliverables use verified evidence and an audit-suitable report, with PDF and SARIF where applicable. 04 Tenant separation Tenant-scoped access, explicit roles and server-side authorisation protect customer records and operational actions. 05 Account security HttpOnly sessions, rotating refresh tokens, TOTP MFA, one-time backup codes and encrypted secrets protect browser accounts. 06 Traceability Assessment jobs, finding changes, retest requests, role changes and sensitive administrative actions produce attributable records. // scope of service Clear operational boundaries Argus Sentinel provides passive intelligence and correlation between assessments. Round-the-clock monitoring and incident response sit outside this service, while certification depends on an independent assessment. Retention, subprocessors, testing permissions and deliverables are agreed for each engagement. // due diligence Security review material A DPA, security FAQ, subprocessor disclosure, sample deliverables and technical answers are available during qualification under appropriate confidentiality terms. DPA Responsible disclosure security.txt // assurance register Assurance status and scope. Each item below states its current scope and status. We identify operating safeguards, voluntary commitments, self-assessments and independent certification separately. Last reviewed 21 September 2026 01 CREST AI Charter Commitment submitted Kotav Labs submitted its commitment to the nine CREST AI Principles on 5 September 2026. Public listing and the badge remain pending. CREST principles 02 CSA AI Trustworthy Pledge Official badge issued CSA issued Kotav Labs the official 2026 Trustworthy AI Pledge badge. Confirmation of the public directory listing remains pending. CSA pledge 03 CSA STAR Level 1 Published self-assessment CSA published Kotav Labs’ CAIQ v4.1 Level 1 self-assessment in the STAR Registry on 14 September 2026. This is a provider self-assessment, not an independent audit. View CSA listing 04 CSA STAR for AI Level 1 Published self-assessment CSA published the Argus AI-CAIQ v1.1.0 self-assessment in the STAR Registry on 14 September 2026. This is a provider self-assessment, not independent certification or audit. View CSA listing 05 NIST CSF 2.0 and AI RMF Frameworks in use Scoped current and target profiles structure our internal improvement programme, with evidence reviews tracked against each profile. NIST CSF 06 OWASP ASVS 5.0 and SAMM Methodology adopted Assessment and development practices reference selected OWASP requirements and retain review evidence. OWASP ASVS 07 NIS2 Internal implementation complete Our scoped internal NIS2 programme has complete control, operating-evidence and management-approval records across governance, risk management, incident handling, continuity, supply-chain security, secure development, cryptography, access control and disclosure. These safeguards remain under continuous review. Applicability and any registration or reporting duties remain subject to the competent authority. EU NIS2 overview 08 ISO/IEC 27001:2022 ISMS programme active Policies, risk records, control ownership and operating evidence form an active ISMS programme. ISO certification guidance 09 MITRE CNA application Application package ready The public disclosure policy and advisory index are published. Authenticated submission, a named backup operational contact and CVE Program acceptance are still required. Public advisory index 10 CISA Secure by Design Pledge Not currently eligible The public roadmap and evidence plan are ready, but Kotav currently has prospects rather than customers in the United States. CISA requires US software customers, so the pledge has not been submitted and will be reassessed after the first qualifying customer. CISA pledge 11 EU Cybersecurity Skills Pledge Submitted for review Kotav Labs submitted its pledge and training initiative for platform review on 21 September 2026. The commitment covers free training for at least 25 EU-based developers and security professionals by 30 September 2027; acceptance and publication remain pending. View submitted pledge 12 SME Climate Hub Commitment active Registration and email activation were completed on 19 September 2026. The emissions baseline is the next operational task; evidence of a public profile has not yet been recorded. SME Climate Commitment 13 ECSO label Issuer and route selected The European DIGITAL SME Alliance label-only route is selected at €600 plus VAT for 12 months. Application, payment and issuer approval remain pending; no label has been awarded. Selected issuer 14 ISO/IEC 42001:2023 Internal implementation complete The scoped AIMS, AI inventory, impact and risk treatment, control mapping, operating evidence, internal audit and management review are complete. Independent accredited certification remains pending. Read implementation record 15 SOC 2 Type II Control baseline implemented The scoped control design, ownership and evidence process are implemented. The independent service-auditor examination and Type II report remain pending. Read implementation record 16 EU Cyber Resilience Act Product controls implemented Secure-development, vulnerability-handling, dependency, release-evidence and support controls are implemented. Product classification and the applicable legal conformity route remain subject to formal determination. Read implementation record 17 DORA ICT supplier controls implemented The customer evidence pack covers security, incidents, resilience testing, continuity, subcontractors, audit cooperation and exit support. DORA does not provide a supplier certificate; customer-specific legal validation remains separate. Read implementation record 18 NIST SP 800-115 / PTES Assessment method implemented Authorisation, scope, discovery, controlled validation, evidence handling, reporting, remediation and retesting follow a repeatable documented method. NIST and PTES do not issue a certificate for this adoption. Read implementation record 19 ISO 22301 Internal BCMS implementation complete The scoped business-impact analysis, continuity strategies, recovery exercises, supplier dependencies, management review and corrective-action process are implemented. Independent accredited certification remains pending. Read implementation record // what supports a claim What supports each status. A policy alone does not prove operation. Public claims require a defined scope, an accountable owner, dated evidence and a recorded review. 01 Authorisation, scope and Rules of Engagement 02 Execution and intervention logs 03 Evidence provenance and specialist decisions 04 Supplier, AI-provider and data-flow reviews 05 Recovery, access and change-control records 06 Reports, remediation guidance and retest outcomes