Security architecture and standards
Documentation of Kwill's security practices, data protection, payment security, infrastructure, and compliance standards.
Cloud Infrastructure
Hosted on Vercel infrastructure, which maintains SOC 2 Type II certification.
Vercel Edge NetworkSOC 2 Type IIGlobal Uptime99.99%DDoS MitigationAlways Active- PCI DSS Level 1
Payment Security
Payments are processed by Stripe. Kwill never stores payment card data.
Stripe PCI CertifiedLevel 1Card Data Handling TokenizedKwill Vault Storage0 Raw Cards Stored Data Privacy & Control
GDPR compliance, role-based permissions, and user data export or deletion.
GDPR & Data OwnershipCompliantData ExportRBAC / Delete
1. Data Encryption
All data encrypted in transit (TLS 1.3) and at rest (AES-256) across all databases and storage services.
2. Payments
Kwill never stores payment card data. All payments processed by Stripe (PCI DSS Level 1 certified).
3. GDPR & Data Ownership
We are GDPR compliant. You own your data. Export or delete at any time.
For detailed privacy practices, read our Privacy Policy .
4. Infrastructure
Hosted on Vercel, which maintains SOC 2 Type II certification. Kwill is actively pursuing its own SOC 2 Type II certification.
5. Access Controls
Role-based permissions. Audit log on Studio and Collective plans.
6. Responsible Disclosure
Report security vulnerabilities directly to our security team:
Security Contact: hello@getkwill.com