Skip to Content

Secure Audit Collection with Kovoco


Soc II Type I certification for you to rest easy.

 

 

SOC 2 Type I


An independent CPA firm, Vigil Assurance, PLLC, examined the design of our security controls for the kAudit system as of May 29, 2026.

What is SOC 2 Type I? SOC 2 is an audit framework from the AICPA. A Type I report evaluates whether security controls are suitably designed at a point in time. 

Request our SOC 2 report

Compliance Support


kAudit is built for teams needing to comply with SOC 2, HIPAA, PCI DSS, GLBA, GDPR, and SOX regulatory requirements. kAudit stores no PHI or PII and it helps you evidence change control over your databases without expanding your sensitive-data footprint.

kAudit supports your compliance program; your organization remains responsible for its overall compliance. Talk to us about how kAudit fits your specific framework. 


Access & authentication


  •     Single sign-on via Microsoft Entra ID (organizational SSO).
  •     Role-based access control over portal actions — Viewer, Analyst, and Admin roles.
  •     Agent authentication via API key with Azure Key Vault-backed tokens; rotate keys from the       portal without redeploying.

Encryption


  • In transit: TLS 1.2 or higher on all connections.
  • At rest: encrypted with Azure-managed keys, or your own customer-managed keys.

Infrastructure & Hosting


kAudit is hosted entirely on Microsoft Azure (US East region), deployed with infrastructure-as-code. Network access to service components is restricted to authorized endpoints via Azure networking policies. Azure's data centers are independently certified (ISO 27001, ISO 27017, ISO 27018, SOC 2), so kAudit runs on certified secure infrastructure.

Change management


Changes to production follow a documented change-management process: peer-reviewed code, approval before deployment, separated development / staging / production environments, and CI/CD pipeline controls.

Monitoring & Logging


Security and performance events are logged and monitored, and capacity, vulnerability, and backup conditions are monitored to support timely detection of and response to issues.

Incident Response


  • Breach notification: if a confirmed security incident may affect your data, we notify you within 72 hours of becoming aware, share reasonable detail, and cooperate with required regulatory notification.
  • Vulnerabilities: we use commercially reasonable efforts to promptly remediate known critical- and high-severity vulnerabilities.


People & Policies


  • Personnel with production access are subject to background checks, confidentiality and IP obligations, and security-awareness training at hire and annually.
  • Information-security policies are centralized and reviewed at least annually.

Shared Responsibility


Security is shared. kAudit secures the platform and its controls. Microsoft Azure secures the underlying infrastructure. You configure roles and access in your tenant, protect your credentials and API keys, and manage your own SQL Server environment. Our SOC 2 report describes the complementary controls we assume on your side.

Found a security issue? 

Email security@kovoco.net. We welcome responsible disclosure and will respond promptly.

Frequently asked questions

Here are some common questions about our company.

kAudit has a SOC 2 Type I (Security) report, audited by Vigil Assurance, PLLC, as of May 29, 2026. Request it under NDA.

No. kAudit stores event and alert metadata only — no PHI or PII.

On Microsoft Azure (US East region).

Yes — TLS 1.2+ in transit, and at rest with Azure-managed or customer-managed keys.

kAudit is built to support these programs and stores no PHI/PII; your organization remains responsible for overall compliance.

The agent reads native SQL Server audit files on the host and sends events over outbound HTTPS (port 443) only, authenticated with a single, rotatable API key.