KAV Labs Trust Center
Everything your security and legal teams need to review KAV Labs: how data moves, how it is protected, and every policy in one place.
How your data flows
KAV Labs is a pipeline, not a destination. We read from your source system, transform records, and write them into your Klaviyo account.
Your source system
We authenticate with credentials you provide and read only the records needed for the integration.
KAV Labs
Records are transformed in transit and encrypted at rest. Raw payloads are purged after 7 days.
Your Klaviyo account
Profiles and events land in the Klaviyo account you own. You remain the controller throughout.
Security at a glance
Policies and documents
Information Security Policy
How we protect information: access control, encryption, incident response, and continuity.
Version 2.0Data Processing Agreement
Our processor commitments, retention periods, breach notification, and transfer mechanisms.
Version 2.0Privacy Policy
What we collect on our website and how we handle business contact data.
Version 2.0Terms of Service
The contractual terms that govern use of the KAV Labs Services.
Version 2.0Subprocessors
The current list of providers we use, what each is used for, and change notifications.
ViewCompliance posture
We would rather be accurate than impressive. Here is exactly where we stand today:
- KAV Labs is not SOC 2 certified and has not completed a SOC 2 audit.
- KAV Labs has not completed a third-party penetration test.
- We are not certified under ISO 27001, PCI DSS, or HITRUST, and we do not process payment card data — card payments are handled by Stripe.
- We act as a processor for Customer Data under GDPR and UK GDPR, and as a service provider under the CCPA/CPRA. Our commitments are set out in the Data Processing Agreement.
- Our security controls are documented in the Information Security Policy and are reviewed at least annually.
If your review requires evidence we have not published, ask us — we will tell you plainly whether we have it.