Skip to main content
Security & Compliance

Security architecture and standards

Documentation of Kwill's security practices, data protection, payment security, infrastructure, and compliance standards.

  • Cloud Infrastructure

    Hosted on Vercel infrastructure, which maintains SOC 2 Type II certification.

    Vercel Edge Network
    SOC 2 Type II
    Global Uptime99.99%
    DDoS MitigationAlways Active
  • Payment Security

    PCI DSS Level 1

    Payments are processed by Stripe. Kwill never stores payment card data.

    Stripe PCI Certified
    Level 1
    Card Data Handling Tokenized
    Kwill Vault Storage0 Raw Cards Stored
  • Data Privacy & Control

    GDPR compliance, role-based permissions, and user data export or deletion.

    GDPR & Data Ownership
    Compliant
    Data Export
    RBAC / Delete

1. Data Encryption

All data encrypted in transit (TLS 1.3) and at rest (AES-256) across all databases and storage services.

2. Payments

Stripe PCI Certified

Kwill never stores payment card data. All payments processed by Stripe (PCI DSS Level 1 certified).

3. GDPR & Data Ownership

We are GDPR compliant. You own your data. Export or delete at any time.

For detailed privacy practices, read our Privacy Policy .

4. Infrastructure

Hosted on Vercel, which maintains SOC 2 Type II certification. Kwill is actively pursuing its own SOC 2 Type II certification.

5. Access Controls

Role-based permissions. Audit log on Studio and Collective plans.

6. Responsible Disclosure

Report security vulnerabilities directly to our security team:

Security Contact: hello@getkwill.com

7. Roadmap

SOC 2 Type II certification

In Progress
Security & Compliance | Kwill