Kiket docs
Compliance

Compliance & audit

What Kiket produces for your auditors, how optional anchor proofs work, and what frameworks we're built for.

Compliance is not a report Kiket generates about your work. Compliance is a side effect of operating inside the twin: every action that matters gets recorded, hashed, exportable, and optionally anchored in a format your auditor can verify without ever talking to us.

Action → hash → anchor → auditor verifies

What gets recorded

Every:

  • Case transition (from / to / actor / time / hash)
  • Approval (granted / denied / comment / approver)
  • Assistive suggestion (inputs / model / reasoning / acceptance)
  • Config change (process edits, case-type changes, new SLAs — via the git-backed .kiket/ repo)
  • Scanner run and finding lifecycle (opened, triaged, remediated, resolved)
  • Privileged admin action (role change, token creation, webhook registration)

...lands in an append-only event log with a cryptographic hash covering the full content.

How anchor proofs work

  1. Events are fingerprinted individually as they happen from a canonical representation.
  2. A scheduled batch job (cadence is configurable) builds a tamper-evident tree over each batch.
  3. The batch root can be written in a single transaction to the Polygon blockchain (low fees, EVM-compatible, public).
  4. The anchoring transaction ID and verification material are stored alongside the event.

Result: given any event, anyone can verify against Polygon that it existed at or before the block timestamp and hasn't been altered since — without trusting us alone. Anchoring is optional; PostgreSQL snapshots and local hash verification remain authoritative for day-to-day operations. Review and generate audit output in Audit Room.

Deep dives

Frameworks we're built for

Kiket is built for operational evidence and immutable history across common compliance programs. The platform implements controls and produces artifacts; external attestation (SOC 2 Type II, HIPAA audit, ISO 27001 certification) is separate and published to the Trust page when complete. Contact us for current status.

AreaHow Kiket helps
SOC 2Evidence for CC controls — access review, change management, incident response
HIPAA / HITECHBreach notification processes, BAA tracking, PHI access evidence
SOXChange management, segregation of duties, immutable approval history
GDPRArticle 30 records, DSAR handling — see Privacy & DSAR playbook
EU AI ActArticle 14 human oversight, assistive suggestion reasoning logs
21 CFR Part 11Electronic signatures, audit trail, closed-system records
ISO 27001Change management, incident response, vendor review
KYC / AMLCustomer review processes, sanctions checks, escalation
FOIAPublic records request handling with response SLAs
eDiscoveryPreservation holds, search, export packages

Attestation status

"Built for" means the platform implements the controls and produces the artifacts. External attestation is published to the Trust page when complete. Contact us for current status.

Exporting evidence

From Audit Room or Settings → Compliance, export scoped evidence for a workspace, date range, and monitored processes:

Pick scope

Workspace, date range, monitored processes, and labels.

Pick framework lens

Choose a framework mapping (SOC 2, HIPAA, etc.). The export includes which events satisfy which control objective.

Pick format

PDF (human-readable), JSON (machine-readable), YAML (config-friendly).

Download

The file includes event data, cryptographic proof bundles, and a verify.sh script your auditor can run against Polygon when anchor proofs exist.

Data residency

  • Default hosting is in the EU (specific regions are listed in order documentation and the trust page).
  • Customer data never leaves the EU on the default plan.
  • Enterprise customers can deploy to their own VPC or on-prem — see Self-host.

DPA + subprocessors

  • Our DPA covers GDPR Article 28.
  • Subprocessor list is public and maintained on the trust page.
  • Customers are notified 30 days before any subprocessor change.

Responsible disclosure

Found a vulnerability? Email security@kiket.dev. We acknowledge within 24 hours and publish postmortems on the public changelog when fixes ship.

On this page