Third Party Index

Snapshot 42302

Document
Trust center
URL
https://trust.delve.co/karumi
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
browser
Size
642886 bytes
SHA-256 (raw)
5d2bd9c6d815bf6989981aa2b95d2a2945741a85356a678c40b8d78097c9052b
SHA-256 (normalized text)
0feb89e3d909c2db95b478420c88e94a676bb2c4f6fe1071c11d115592285510

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Karumi Trust Center
Karumi is in compliance with security best practices, has implemented and is monitoring comprehensive controls, and maintains policies to outline its security procedures.
Compliance
Links
Privacy PolicyTerms of Service
Resources
Karumi - SOC 2 Type 2 Report
Information Security Management System Manual
Business Impact Assessment Policy
Data Protection, Accountability, and Privacy by Design Policy
Business Continuity and Disaster Recovery
Controls
Technology asset inventory
Secure media disposal
Technology assets inventoried
Business continuity and disaster recovery plan
Emergency operations continuity
Multi-availability zone deployment
Database backups
Capacity and performance monitoring
Customer notification for major changes
Material system change communication
Cloud provider physical access review
Cloud services security
HIPAA Security Rule policy acknowledgment
Compliance requirements documentation
Baseline configuration management
Centralized log collection and monitoring
Production key management
Encryption at rest
Encryption in transit
Organizational structure documentation
Security roles and responsibilities
Governance committee bylaws
Board security briefings
Annual strategic planning
Data classification and access control
Customer data deletion
Data retention and deletion policy
Automated decision-making policy
Age verification and parental consent
Data protection impact assessment
Internal GDPR compliance assessments
Lawful basis assessment
Removable media controls
Anti-malware protection
Remote work policy
Employee confidentiality agreements
Disciplinary process
Contractor code of conduct acknowledgment
Termination access revocation
Employee code of conduct acknowledgment
Access control procedures
Quarterly access reviews
Least-privilege access for production infrastructure
Session timeout enforcement
Password policy
Incident response procedures
Security concern resolution
Security incident logging
Regulatory authority communication
Security documentation availability
Internal Audit Program
Internal audit program
Mobile device management
Secure connection requirements
Network firewall
Firewall rule management
Network architecture documentation
Visitor management policy
Clear desk and screen policy
Cabling and utility security
Security in project management
Annual risk assessment
Security and privacy risk management
Documented security & privacy risk management process
Annual risk assessments performed
Cybersecurity insurance
Source code access controls
Source code change approval
Environment and tenant segmentation
Static application security testing
Secure development procedures
Security awareness training
Intrusion detection
Customer support availability
Time synchronization
Contractor confidentiality agreements
Vendor confidentiality and privacy agreements
Contractual security commitments
Penetration testing
Outsourced development security
Security community participation
Patch management
Vulnerability scanning and remediation
Web application firewall
ISMS Stakeholder Management
ISMS Context Analysis
Annual security policy acknowledgment
Management Review
Continual Improvement and Corrective Action
Subprocessors
OpenAIAI & ML Services
RenderCloud Infrastructure & Platform Services