Security at Kultify
We protect your employees' feedback data with AES-256 encryption, TLS in transit, and hosting in Europe and Germany. Kultify was built from the ground up with a focus on data protection and information security.
Anna Müller
Product Development
How we protect your data
Encryption, access control, and monitoring at every layer of the platform.
End-to-end protected
AES-256 encryption for data at rest, TLS for data in transit. All sensitive information is continuously protected.
SSO, 2FA & Audit Logs
SSO via OpenID Connect (OIDC) plus 2FA on every account. Least-privilege principle, audit logs for administrative access.
Continuous Testing
Continuous, automated vulnerability scanning around the clock.
Real-time Monitoring
Automated alerts for suspicious activities.
Instant detection and reporting.
Device Security
Enterprise-grade antivirus scanners with real-time detection. Full disk encryption.
Protection against Phishing & Spoofing
SPF and DMARC implementation against spoofing and phishing attacks.
GDPR-compliant from the start
Kultify meets all GDPR requirements. We sign a Data Processing Agreement (DPA) per Art. 28 GDPR with every customer and work exclusively with EU-based sub-processors that meet strict security requirements.
Enterprise-grade Infrastructure
Application services run on Hetzner in Germany, managed databases on OVH (Germany location). Both providers are ISO 27001 certified. Data does not leave the EU; no US sub-processors for primary data. Daily encrypted backups at two geographically separated locations in Germany.
- DPA per Art. 28 GDPR
- Hetzner & OVH, Germany
- Secure deletion after contract end
- Retention period defined in DPA
- Daily encrypted backups
- RTO < 48 h, RPO < 24 h
- EU sub-processors under DPA
Secure Development & Operations
From the first line of code to ongoing operations. Security is integrated into every step of our development process.
SAST
Regular static application security testing to detect vulnerabilities in code.
SCA
Software Composition Analysis for third-party dependencies.
Firewall
Enterprise-grade stateful firewalls with predefined rulesets.
AI-augmented code reviews
AI-assisted analysis on every pull request catches security issues before they ship to production.
Security Training
Continuous training, phishing simulations, password management.
Incident Response
Structured incident management with defined escalation paths and post-mortems.
Artificial Intelligence at Kultify
For text analysis and translations, only European AI providers process your data. All data processing is fully GDPR-compliant.
No Training on Customer Data
All AI providers are contractually prohibited from using submitted prompts as training data.
EU AI Act: limited risk
Our AI system is classified as a limited risk system under the EU AI Act. No decisions or decision proposals are generated based on AI results.
Transparency for Users
At all points in the platform where users interact with AI, it is clearly indicated that the results and analyses are AI-generated.
Security beyond the code
Onboarding, devices, offboarding, and training are part of the same routine.
- Employee Onboarding
- All employees sign confidentiality agreements. Security policies are communicated from day one.
- Device Security
- Full disk encryption and automatic updates on all company devices.
- Offboarding
- Access revocation within 24 hours. Deactivation of all physical and digital credentials.
- Training
- Ongoing security awareness programs, phishing simulations, and password management training.
Legal Documents
Transparency is important to us. You can find all relevant documents in our Trust Center.
Frequently Asked Questions
Everything about security and privacy at Kultify
Still have questions? Contact our
Privacy
Security
Artificial Intelligence
Compliance
Still have questions? Contact our
Still have questions about security?
Our team is happy to answer all questions about security and privacy. Schedule a short call with us.