Security at Kwata Team
Security is the foundation of everything we build. Our PESNO framework puts Privacy, Ethics and Integrity, Security, Network Isolation, and OWASP practices into every system we deploy.
The PESNO Security Framework
PESNO is a way of working that shapes every change. Before every change we ask: "Does this follow PESNO principles?"
Privacy
Your data is protected by design
Privacy
Your data is protected by design
Ethics & Integrity
Transparent, honest, and trustworthy practices
Ethics & Integrity
Transparent, honest, and trustworthy practices
Security
Layered protection
Security
Layered protection
Network Isolation
Segmented infrastructure
Network Isolation
Segmented infrastructure
OWASP
Industry security standards
OWASP
Industry security standards
Security by Design
Security is foundational. These principles guide every decision we make.
Verify, Never Assume
Internal services authenticate to each other, and datastores are never reachable from the internet.
Defense in Depth
Multiple layers of security controls ensure that if one fails, others protect your data.
Principle of Least Privilege
Systems and users only have the minimum access necessary to perform their functions.
Fail Securely
When systems fail, they default to a secure state rather than exposing data.
Continuous Monitoring
We continuously monitor for threats and respond to incidents within hours.
Regular Updates
We scan our systems for known vulnerabilities every day and fix critical ones first.
Frameworks We Align With
We use precise language about where we stand. Kwata Team is built to the SOC 2 Trust Services Criteria and our internal PESNO standard, and is aligned with the privacy laws below. A formal third-party SOC 2 attestation and ISO 27001 certification are on our roadmap, and we will say we hold them only once we do.
Privacy: aligned
- PIPEDA (Canadian federal privacy law)
- Alberta PIPA (provincial privacy law)
- CASL (consent & unsubscribe in every email)
Security: built to
- AES-256 encryption at rest
- TLS 1.2+/1.3 in transit
- SOC 2 Trust Services Criteria (aligned)
- OWASP Top 10 secure-coding practices
On our roadmap
- SOC 2 Type II attestation (accredited auditor)
- ISO/IEC 27001 certification
Hosting & payments
- Your data is never used to train AI and never sold
- Payments handled by PCI-DSS-compliant processors, and card data never touches our servers
Report a Security Issue
If you discover a security vulnerability, please report it responsibly:
- Email: security@kwatateam.com
- Response Time: Acknowledged within one business day