Kultify

Security at Kultify

We protect your employees' feedback data with AES-256 encryption, TLS in transit, and hosting in Europe and Germany. Kultify was built from the ground up with a focus on data protection and information security.

Secure Platform Access
Anna Müller

Anna Müller

Product Development

Protocol active
AES-256 encrypted
Access restricted
Last accessToday, 09:14
EncryptionTLS 1.3
GDPR-compliant
Hosting in Europe and Germany
AES-256 & TLS
ISO 27001 hosting providers

How we protect your data

Encryption, access control, and monitoring at every layer of the platform.

Encryption

End-to-end protected

AES-256 encryption for data at rest, TLS for data in transit. All sensitive information is continuously protected.

Encryption
data:••••••••••••
algo:AES-256-GCM
tls:v1.3
Encrypted
Access Control

SSO, 2FA & Audit Logs

SSO via OpenID Connect (OIDC) plus 2FA on every account. Least-privilege principle, audit logs for administrative access.

anna.mueller@firma.de
••••••••
2FA-Code
4
7
2
9
1
8
Automated Vulnerability Scanning

Continuous Testing

Continuous, automated vulnerability scanning around the clock.

Scan-Ergebnis4/4 bestanden
SQL Injection
XSS (Cross-Site Scripting)
Auth Bypass
CSRF Token Validation
Monitoring

Real-time Monitoring

Automated alerts for suspicious activities.

Instant detection and reporting.

Activity LogLive
09:14Login successful
09:12API access
09:08Export blocked
09:03Password changed
Endpoint Protection

Device Security

Enterprise-grade antivirus scanners with real-time detection. Full disk encryption.

MacBook Pro
Device #1
EncryptionActive
AntivirusUp to date
FirewallActive
Email Security

Protection against Phishing & Spoofing

SPF and DMARC implementation against spoofing and phishing attacks.

Suspicious email detected
From:no-reply@fak3-bank.com
Subj:Account verification urgent
Blocked

GDPR-compliant from the start

Kultify meets all GDPR requirements. We sign a Data Processing Agreement (DPA) per Art. 28 GDPR with every customer and work exclusively with EU-based sub-processors that meet strict security requirements.

DE

Enterprise-grade Infrastructure

Application services run on Hetzner in Germany, managed databases on OVH (Germany location). Both providers are ISO 27001 certified. Data does not leave the EU; no US sub-processors for primary data. Daily encrypted backups at two geographically separated locations in Germany.

  • DPA per Art. 28 GDPR
  • Hetzner & OVH, Germany
  • Secure deletion after contract end
  • Retention period defined in DPA
  • Daily encrypted backups
  • RTO < 48 h, RPO < 24 h
  • EU sub-processors under DPA

Secure Development & Operations

From the first line of code to ongoing operations. Security is integrated into every step of our development process.

SAST

Regular static application security testing to detect vulnerabilities in code.

SCA

Software Composition Analysis for third-party dependencies.

Firewall

Enterprise-grade stateful firewalls with predefined rulesets.

AI-augmented code reviews

AI-assisted analysis on every pull request catches security issues before they ship to production.

Security Training

Continuous training, phishing simulations, password management.

Incident Response

Structured incident management with defined escalation paths and post-mortems.

Artificial Intelligence at Kultify

For text analysis and translations, only European AI providers process your data. All data processing is fully GDPR-compliant.

No Training on Customer Data

All AI providers are contractually prohibited from using submitted prompts as training data.

EU AI Act: limited risk

Our AI system is classified as a limited risk system under the EU AI Act. No decisions or decision proposals are generated based on AI results.

Transparency for Users

At all points in the platform where users interact with AI, it is clearly indicated that the results and analyses are AI-generated.

Security beyond the code

Onboarding, devices, offboarding, and training are part of the same routine.

01.
Employee Onboarding
All employees sign confidentiality agreements. Security policies are communicated from day one.
02.
Device Security
Full disk encryption and automatic updates on all company devices.
03.
Offboarding
Access revocation within 24 hours. Deactivation of all physical and digital credentials.
04.
Training
Ongoing security awareness programs, phishing simulations, and password management training.

Legal Documents

Transparency is important to us. You can find all relevant documents in our Trust Center.

Frequently Asked Questions

Everything about security and privacy at Kultify

Still have questions? Contact our

Privacy

Security

Artificial Intelligence

Compliance

Still have questions? Contact our

Still have questions about security?

Our team is happy to answer all questions about security and privacy. Schedule a short call with us.