Third Party Index

Snapshot 20335

Document
Trust center
URL
https://kotavlabs.com/en/security
Fetched
HTTP status
200
Content type
text/html
Fetch mode
static
Size
79746 bytes
SHA-256 (raw)
dea519f30a4eadcf79e03a2f0115a12c3efb4755659c3b1f84f9ea75e74e553c
SHA-256 (normalized text)
31fd83d371c7560b371e7244acc45004d996614241f3947d9bcf5566b320f626

Normalized text

Scripts and page chrome removed; this is what change detection compares.

// security & trust
Evidence you can review. Controls you can verify.
Kotav Labs delivers authorised security assessments through a controlled engagement model. This page states what we protect, how delivery is governed and where our boundaries are.
Request the security pack Responsible disclosure
KOTAV / TRUST CENTER
Authorised testing
EU-hosted evidence
Reviewed delivery
Tenant separation
// operating safeguards
Security built into the delivery model.
They apply from written authorisation through to reviewed evidence and traceable delivery.
01
Authorised testing
Testing starts only after scope, hosts, dates, rate limits, write permissions and Rules of Engagement are documented.
02
EU-hosted evidence
Assessment infrastructure and evidence are hosted in Germany. Subprocessors and any additional processing locations are disclosed per engagement.
03
Reviewed delivery
Material findings receive specialist review. Deliverables use verified evidence and an audit-suitable report, with PDF and SARIF where applicable.
04
Tenant separation
Tenant-scoped access, explicit roles and server-side authorisation protect customer records and operational actions.
05
Account security
HttpOnly sessions, rotating refresh tokens, TOTP MFA, one-time backup codes and encrypted secrets protect browser accounts.
06
Traceability
Assessment jobs, finding changes, retest requests, role changes and sensitive administrative actions produce attributable records.
// scope of service
Clear operational boundaries
Argus Sentinel provides passive intelligence and correlation between assessments. Round-the-clock monitoring and incident response sit outside this service, while certification depends on an independent assessment. Retention, subprocessors, testing permissions and deliverables are agreed for each engagement.
// due diligence
Security review material
A DPA, security FAQ, subprocessor disclosure, sample deliverables and technical answers are available during qualification under appropriate confidentiality terms.
DPA Responsible disclosure security.txt
// assurance register
Assurance status and scope.
Each item below states its current scope and status. We identify operating safeguards, voluntary commitments, self-assessments and independent certification separately.
Last reviewed 21 September 2026
01
CREST AI Charter
Commitment submitted
Kotav Labs submitted its commitment to the nine CREST AI Principles on 5 September 2026. Public listing and the badge remain pending.
CREST principles
02
CSA AI Trustworthy Pledge
Official badge issued
CSA issued Kotav Labs the official 2026 Trustworthy AI Pledge badge. Confirmation of the public directory listing remains pending.
CSA pledge
03
CSA STAR Level 1
Published self-assessment
CSA published Kotav Labs’ CAIQ v4.1 Level 1 self-assessment in the STAR Registry on 14 September 2026. This is a provider self-assessment, not an independent audit.
View CSA listing
04
CSA STAR for AI Level 1
Published self-assessment
CSA published the Argus AI-CAIQ v1.1.0 self-assessment in the STAR Registry on 14 September 2026. This is a provider self-assessment, not independent certification or audit.
View CSA listing
05
NIST CSF 2.0 and AI RMF
Frameworks in use
Scoped current and target profiles structure our internal improvement programme, with evidence reviews tracked against each profile.
NIST CSF
06
OWASP ASVS 5.0 and SAMM
Methodology adopted
Assessment and development practices reference selected OWASP requirements and retain review evidence.
OWASP ASVS
07
NIS2
Internal implementation complete
Our scoped internal NIS2 programme has complete control, operating-evidence and management-approval records across governance, risk management, incident handling, continuity, supply-chain security, secure development, cryptography, access control and disclosure. These safeguards remain under continuous review. Applicability and any registration or reporting duties remain subject to the competent authority.
EU NIS2 overview
08
ISO/IEC 27001:2022
ISMS programme active
Policies, risk records, control ownership and operating evidence form an active ISMS programme.
ISO certification guidance
09
MITRE CNA application
Application package ready
The public disclosure policy and advisory index are published. Authenticated submission, a named backup operational contact and CVE Program acceptance are still required.
Public advisory index
10
CISA Secure by Design Pledge
Not currently eligible
The public roadmap and evidence plan are ready, but Kotav currently has prospects rather than customers in the United States. CISA requires US software customers, so the pledge has not been submitted and will be reassessed after the first qualifying customer.
CISA pledge
11
EU Cybersecurity Skills Pledge
Submitted for review
Kotav Labs submitted its pledge and training initiative for platform review on 21 September 2026. The commitment covers free training for at least 25 EU-based developers and security professionals by 30 September 2027; acceptance and publication remain pending.
View submitted pledge
12
SME Climate Hub
Commitment active
Registration and email activation were completed on 19 September 2026. The emissions baseline is the next operational task; evidence of a public profile has not yet been recorded.
SME Climate Commitment
13
ECSO label
Issuer and route selected
The European DIGITAL SME Alliance label-only route is selected at €600 plus VAT for 12 months. Application, payment and issuer approval remain pending; no label has been awarded.
Selected issuer
14
ISO/IEC 42001:2023
Internal implementation complete
The scoped AIMS, AI inventory, impact and risk treatment, control mapping, operating evidence, internal audit and management review are complete. Independent accredited certification remains pending.
Read implementation record
15
SOC 2 Type II
Control baseline implemented
The scoped control design, ownership and evidence process are implemented. The independent service-auditor examination and Type II report remain pending.
Read implementation record
16
EU Cyber Resilience Act
Product controls implemented
Secure-development, vulnerability-handling, dependency, release-evidence and support controls are implemented. Product classification and the applicable legal conformity route remain subject to formal determination.
Read implementation record
17
DORA
ICT supplier controls implemented
The customer evidence pack covers security, incidents, resilience testing, continuity, subcontractors, audit cooperation and exit support. DORA does not provide a supplier certificate; customer-specific legal validation remains separate.
Read implementation record
18
NIST SP 800-115 / PTES
Assessment method implemented
Authorisation, scope, discovery, controlled validation, evidence handling, reporting, remediation and retesting follow a repeatable documented method. NIST and PTES do not issue a certificate for this adoption.
Read implementation record
19
ISO 22301
Internal BCMS implementation complete
The scoped business-impact analysis, continuity strategies, recovery exercises, supplier dependencies, management review and corrective-action process are implemented. Independent accredited certification remains pending.
Read implementation record
// what supports a claim
What supports each status.
A policy alone does not prove operation. Public claims require a defined scope, an accountable owner, dated evidence and a recorded review.
01
Authorisation, scope and Rules of Engagement
02
Execution and intervention logs
03
Evidence provenance and specialist decisions
04
Supplier, AI-provider and data-flow reviews
05
Recovery, access and change-control records
06
Reports, remediation guidance and retest outcomes