Information Security Policy

Version 2.0 · Effective August 28, 2026

Information Security Policy

KAV Labs LLC

838 Walker Road, Suite 21-2

Dover, DE 19904

Version:

2.0

Owner:

KAV Labs Leadership Team

Effective Date:

August 28, 2026

Last Reviewed:

August 28, 2026

1. Purpose

This policy sets out how KAV Labs LLC protects the confidentiality, integrity, and availability of information belonging to the company, our customers, and our partners. It applies to all employees, contractors, and third parties who handle company data.

2. Scope

This policy covers all information assets, whether stored digitally or physically, including:

  • Customer data (including personal data)
  • Company business information
  • Source code and intellectual property
  • Employee and contractor information

3. Roles & Responsibilities

KAV Labs Leadership Team:

Overall responsibility for information security.

All Employees & Contractors:

Follow this policy and report security incidents promptly.

Third-Party Vendors:

Must meet KAV Labs' security standards as per contracts and DPAs.

4. Access Control

  • Access to systems and data is granted on a least privilege basis.
  • All accounts must be protected with strong passwords (minimum 12 characters) and MFA where supported.
  • Access to production systems is limited to personnel who require it.
  • Access rights are reviewed periodically and on any change of role.
  • Accounts of departing staff/contractors are revoked immediately.

5. Encryption

  • All data transmitted between customers, KAV Labs, and third-party platforms is encrypted in transit using TLS 1.2 or higher.
  • Data at rest is encrypted using AES-256.
  • Third-party API credentials and access tokens supplied by customers are stored encrypted and are never written to application logs.
  • Backups are encrypted at rest.

6. Device & Network Security

KAV Labs requires controls to protect all company-owned and managed devices:

  • Anti-malware software installed and active
  • Endpoint encryption enabled
  • Firewall protections enabled
  • Locked-down administrative privileges
  • Login password required
  • Automatic screen timeout and lock
  • Operating systems and applications kept up to date with security patches

Use of public Wi-Fi requires a VPN.

7. Data Handling

  • Personal data is processed only for its intended purpose and in line with applicable laws (e.g., GDPR) and Data Processing Agreements.
  • Confidential or personal data must not be stored on personal devices unless explicitly approved and secured.
  • Customer data is never used to train artificial intelligence or machine learning models, and is never sold, rented, or licensed.
  • Data must be securely deleted when no longer needed.

8. Data Retention

KAV Labs retains data only as long as it is needed to operate the Services:

Data categoryRetention period
Raw inbound webhook payloads7 days from receipt, then automatically purged
Application and diagnostic logs30 days from creation, then automatically purged
Integration configuration and stored credentialsDuration of the agreement; deleted within 30 days of termination
Sync state and identifier mappings (e.g. external record ID mapped to Klaviyo profile ID)Retained for the duration of the agreement so that records are updated rather than duplicated; deleted within 30 days of termination
Encrypted backupsRolling backup window, then automatically overwritten
Billing and account recordsAs required by law; contains Customer billing contacts only, no end-customer Personal Data

On termination, customer data is deleted within thirty (30) days as described in the Data Processing Agreement.

9. Secure Development

  • Source code is maintained in access-controlled repositories that require authentication and MFA.
  • Changes are reviewed before being released to production.
  • Development and production environments are separated, and production credentials are not used outside production.
  • Secrets and credentials are held in a managed secret store, never committed to source control.
  • Production customer data is not used for development or testing purposes.

10. Vulnerability Management & Testing

Operating systems, application dependencies, and infrastructure components are kept current with security patches. Reported and identified vulnerabilities are triaged by severity and remediated within the following timelines:

  • Critical: within 2 days
  • High: within 7 days
  • Medium: within 30 days
  • Low: within 90 days

Note: KAV Labs has not completed a third-party penetration test. Where a customer's security review requires one, contact us to discuss scope and timing.

11. Incident Response

All security incidents (data breaches, malware infections, unauthorized access) must be reported immediately to the designated security lead.

The KAV Labs Leadership Team coordinates investigation, containment, and notification as required by law. Affected customers are notified without undue delay and within seventy-two (72) hours of confirming a personal data breach affecting their data.

12. Business Continuity & Disaster Recovery

  • Critical data is backed up on a regular schedule to encrypted, access-controlled storage.
  • Restoration from backup is tested periodically to confirm backups are usable.
  • Integrations are designed to resume and reconcile after an outage, so that a period of unavailability does not result in permanently missed records.
  • Specific recovery time and recovery point objectives are available to customers on request.

13. Vendor Management

  • Vendors with access to KAV Labs' data must have appropriate security measures in place.
  • Security due diligence is performed before engaging vendors.
  • Our current subprocessors are published at kavlabs.co/subprocessors.

14. Compliance Posture

We state our compliance position plainly rather than implying certifications we do not hold:

  • KAV Labs is not SOC 2 certified and has not completed a SOC 2 audit.
  • KAV Labs is not certified under ISO 27001, PCI DSS, or HITRUST.
  • KAV Labs does not store or process payment card data; card payments are handled by our payment processor.
  • KAV Labs acts as a processor under the GDPR and UK GDPR, and as a service provider under the CCPA/CPRA, subject to the Data Processing Agreement.
  • This policy is aligned to widely accepted security practices.

15. Reporting a Vulnerability

If you believe you have found a security vulnerability in a KAV Labs product or website, email teamkav@kavlabs.co with the subject line "Security Vulnerability Report". Please include steps to reproduce, the affected URL or endpoint, and any supporting evidence.

We acknowledge reports within two (2) business days and will keep you informed through remediation. We ask that you do not access, modify, or delete data belonging to others, avoid degradation of service, and give us reasonable time to remediate before public disclosure. We will not pursue legal action against researchers who follow these guidelines in good faith.

16. Policy Review

This policy is reviewed at least annually or after significant changes to KAV Labs' business or systems.

We will provide notice of material changes to this document via email to account contacts and by posting an updated version here.