Third Party Index

Snapshot 45776

Document
Trust center
URL
https://kavlabs.co/trust
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
26613 bytes
SHA-256 (raw)
62461cd163eb3029217d3dbdbce679be62fcdd2a7ab6bf6eeadc757fc46ac79d
SHA-256 (normalized text)
054a0d70d7b3d00f657a1318b5e69c09dd4ef780677b08adaeb286ff7716f662

Normalized text

Scripts and page chrome removed; this is what change detection compares.

KAV Labs Trust Center
Everything your security and legal teams need to review KAV Labs: how data moves, how it is protected, and every policy in one place.
How your data flows
KAV Labs is a pipeline, not a destination. We read from your source system, transform records, and write them into your Klaviyo account.
Your source system
We authenticate with credentials you provide and read only the records needed for the integration.
KAV Labs
Records are transformed in transit and encrypted at rest. Raw payloads are purged after 7 days.
Your Klaviyo account
Profiles and events land in the Klaviyo account you own. You remain the controller throughout.
Security at a glance
Encryption in transit (TLS 1.2 or higher) and at rest (AES-256)
Multi-factor authentication required for all personnel accounts
Least-privilege, need-to-know access — and access is logged
7-day raw webhook payload retention, 30-day log retention
72-hour breach notification commitment
No AI or machine learning model training on Customer Data
No sale, rental, or licensing of Customer Data
Policies and documents
Information Security Policy
How we protect information: access control, encryption, incident response, and continuity.
Version 2.0
Data Processing Agreement
Our processor commitments, retention periods, breach notification, and transfer mechanisms.
Version 2.0
Privacy Policy
What we collect on our website and how we handle business contact data.
Version 2.0
Terms of Service
The contractual terms that govern use of the KAV Labs Services.
Version 2.0
Subprocessors
The current list of providers we use, what each is used for, and change notifications.
View
Compliance posture
We would rather be accurate than impressive. Here is exactly where we stand today:
We are not certified under ISO 27001, PCI DSS, or HITRUST, and we do not process payment card data — card payments are handled by Stripe.
We act as a processor for Customer Data under GDPR and UK GDPR, and as a service provider under the CCPA/CPRA. Our commitments are set out in the Data Processing Agreement.
Our security controls are documented in the Information Security Policy and are reviewed at least annually.
If your review requires evidence we have not published, ask us — we will tell you plainly whether we have it.