Skip to main content

Security Exhibit

Last revised: July 2, 2026

This Security Exhibit describes KubernoGRC’s baseline security controls for the Services and Customer responsibilities. Capitalized terms have the meanings in the Agreement.

A. Information Security Program

KubernoGRC maintains an information security program with administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of Customer Data. KubernoGRC’s security program is aligned with ISO 27001 and SOC2 standards. KubernoGRC will make current audit reports or certification letters available to Customer upon request under appropriate confidentiality obligations. KubernoGRC will notify Customer if a material change occurs to its certification status.

B. Access Control

KubernoGRC enforces role-based access controls and the principle of least privilege, and assigns a unique user ID to each user. Multi-factor authentication (MFA) is required for administrative access to production systems and administrative interfaces. Semi-annual access reviews are conducted to validate that access rights remain appropriate. Access is revoked promptly upon employee departure or role change.

C. Authentication

KubernoGRC supports Single Sign-On (SSO) using industry-standard protocols. Password policies are aligned to current best practices.

D. Encryption

Customer Data is encrypted in transit using TLS 1.2 or higher. Customer Data is encrypted at rest using industry-standard algorithms, such as AES-256. Encryption key management follows least-privilege and segregation of duties principles.

E. Vulnerability and Patch Management

KubernoGRC performs routine vulnerability scanning, prioritizes remediation based on risk, and applies security patches according to severity. KubernoGRC also engages qualified external security firms to conduct annual third-party penetration testing, and material findings are remediated on a risk-based schedule.

F. Logging and Monitoring

KubernoGRC logs security events for authentication, authorization, administrative actions, and data access. Anomalous activity generates alerts that are investigated by KubernoGRC’s security team.

G. Network Security

KubernoGRC segments its production network and controls traffic using firewalls and security groups. Only necessary services are exposed to the internet, and DDoS protections are provided by the hosting infrastructure.

H. Business Continuity and Disaster Recovery

KubernoGRC maintains documented business continuity and disaster recovery (BCDR) plans, backs up critical data, tests restoration periodically, and defines recovery objectives. BCDR plans are reviewed and tested at least annually.

I. Secure Development

KubernoGRC follows a secure software development life cycle (SDLC) that includes peer code review, dependency vulnerability management, change management, and version control.

J. Incident Response

KubernoGRC maintains defined incident response procedures that cover detection, triage, escalation, containment, eradication, recovery, and post-incident review. Where Personal Information is implicated, KubernoGRC will notify Customer as set out in the Agreement. KubernoGRC’s incident response program is tested at least annually through tabletop exercises or simulations. Post-incident reviews are conducted and material findings are incorporated into program improvements.

K. Third-Party Risk

KubernoGRC performs risk-based due diligence on third-party providers, imposes contractual security obligations, and monitors those providers on an ongoing basis appropriate to the level of risk. Background checks are conducted on KubernoGRC employees and contractors with access to production systems or Customer Data prior to granting such access. All such personnel are subject to confidentiality obligations. Annual security reviews are conducted for material subprocessors.

L. Data Retention and Deletion

Data retention is aligned to contractual and legal obligations, and KubernoGRC uses secure deletion procedures. Customer-initiated deletion is supported as described in the Agreement. Upon termination or expiration of the Agreement, KubernoGRC will retain Customer Data for a maximum of 180 days following the effective date of termination to allow Customer to export Customer Data. After the retention period, KubernoGRC will securely delete or destroy all Customer Data in identifiable form. Upon Customer request, KubernoGRC will provide written confirmation of deletion within 30 days of completion.

M. Usage Data Reference

KubernoGRC’s collection and use of ‘Usage Data’ (as defined in the Agreement) is limited to operational telemetry and configuration metrics for service improvement and insights. Usage Data does not include Personal Information and will not permit reconstruction of Customer Data. Usage Data is subject to the same security and confidentiality controls described in this Exhibit.

N. Physical Security and Hosting

KubernoGRC’s production infrastructure is hosted on AWS cloud infrastructure. Physical security of production data centers is managed by AWS and is covered by their independent security certifications, including SOC 2 Type II and ISO 27001. KubernoGRC does not operate its own physical data centers. See Subprocessors List for additional information.

O. Customer Responsibilities

In addition to responsibilities outlined in the Acceptable Use Policy, Customer is responsible for:

(i) configuring SSO/MFA and role-based permissions

(ii) safeguarding Customer Credentials

(iii) not introducing Sensitive Information unless expressly permitted

(iv) maintaining Customer Components

(v) promptly notifying KubernoGRC of suspected compromise

This Security Exhibit may be updated by KubernoGRC from time to time to reflect improvements to security controls, provided updates do not materially reduce protections for Customer Data.