KAV Labs Trust Center

Everything your security and legal teams need to review KAV Labs: how data moves, how it is protected, and every policy in one place.

How your data flows

KAV Labs is a pipeline, not a destination. We read from your source system, transform records, and write them into your Klaviyo account.

Your source system

We authenticate with credentials you provide and read only the records needed for the integration.

KAV Labs

Records are transformed in transit and encrypted at rest. Raw payloads are purged after 7 days.

Your Klaviyo account

Profiles and events land in the Klaviyo account you own. You remain the controller throughout.

Security at a glance

Encryption in transit (TLS 1.2 or higher) and at rest (AES-256)
Multi-factor authentication required for all personnel accounts
Least-privilege, need-to-know access — and access is logged
7-day raw webhook payload retention, 30-day log retention
72-hour breach notification commitment
No AI or machine learning model training on Customer Data
No sale, rental, or licensing of Customer Data

Compliance posture

We would rather be accurate than impressive. Here is exactly where we stand today:

  • KAV Labs is not SOC 2 certified and has not completed a SOC 2 audit.
  • KAV Labs has not completed a third-party penetration test.
  • We are not certified under ISO 27001, PCI DSS, or HITRUST, and we do not process payment card data — card payments are handled by Stripe.
  • We act as a processor for Customer Data under GDPR and UK GDPR, and as a service provider under the CCPA/CPRA. Our commitments are set out in the Data Processing Agreement.
  • Our security controls are documented in the Information Security Policy and are reviewed at least annually.

If your review requires evidence we have not published, ask us — we will tell you plainly whether we have it.