generated: '2026-07-27' method: searched probe: true url: https://www.kraken.tech/legal/trust-center source: https://www.kraken.tech/legal/trust-center summary: >- Kraken publishes a substantive Trust Center inside its legal hub (not at trust.kraken.tech, which does not resolve — which is why the automated probe missed it). It names real certifications and attestations, describes the security architecture of the platform, and states that Kraken is a processor whose clients choose deployment region. Reports themselves are available to clients and prospects on request, not for anonymous download. certifications: - ISO/IEC 27001:2022 - SOC 1 Type 2 - SOC 2 Type 2 certification_detail: - name: ISO/IEC 27001:2022 scope: Information Security Management System (ISMS) verbatim: >- "Kraken holds ISO/IEC 27001:2022 certification and uses ISO27001 as the basis for our Information Security Management System." - name: SOC 1 Type 2 / SOC 2 Type 2 scope: Kraken Customer and Kraken Flex; Security, Availability and Confidentiality criteria cadence: Published twice annually verbatim: >- "Kraken's Customer and Kraken Flex maintain SOC 1 Type 2 and SOC 2 Type 2 attestations. These reports are published on a twice-annual basis to enable our clients with various reporting schedules to meet their necessary assurance needs." pci_dss: kraken_certified: false model: delegated verbatim: >- "Credit card processing is not Kraken's mission. This is why we partner with trusted payment providers like Stripe to handle all payment transactions on your behalf... Your card details never touch Kraken's systems, and our payment partners (e.g. Stripe) are certified to the highest industry standards (PCI DSS Level 1)." note: >- Clients using their own payment provider carry their own PCI compliance. Kraken makes no PCI DSS certification claim for itself. data_protection: gdpr_alignment: true verbatim: 'We align with General Data Protection Regulation (GDPR) take this as the standard across the business.' dpo: dpo@kraken.tech privacy_notice: https://www.kraken.tech/legal/privacy-notice cookie_notice: https://www.kraken.tech/legal/cookie-notice dpa: https://www.kraken.tech/legal/dpa subprocessors: https://www.kraken.tech/legal/subprocessors subprocessor_change_notification: true data_residency: >- Clients may deploy Kraken services in any supported region; Kraken will not relocate a client's workspace without prior consent. data_sale: 'Kraken does not sell client data or use it for advertising purposes.' transfer_impact_assessments: documented security_architecture: hosting: Amazon Web Services tenancy: >- Kraken Customer Platform and Kraken Field Platform are single-tenant by default, with isolated network virtualisation, dedicated security controls, and optional log feeds into client SIEM tooling. encryption_at_rest: AES-256 (databases and other stores, e.g. S3) encryption_in_transit: Mandatory TLS 1.2+; known secure TLS 1.2 cipher suites and TLS 1.3 sdlc: >- Secure SDLC integrated into CI/CD with SAST and Software Composition Analysis on every build, and vulnerability analysis before, during and after deployment. patching: Continuous deployment enabling >100 deployments daily, so patches reach client environments quickly. access_control: - Multi-factor authentication across Kraken access points (remote and in office) - Role-based access control with regular privileged access permission audits - Customisable roles and access levels - SAML integration with client identity providers for Kraken Customer Platform security_operations: - Continuous security monitoring - Threat detection with automation and machine learning - Regular security assessments - Incident response procedures and a dedicated security operations team - Disaster recovery capabilities employee_controls: - Mandatory security and privacy awareness training with annual refreshers - Role-specific security training based on job function and access level - Unique credentials per employee; regular privileged access review report_access: anonymous_download: false channels: [Client Requests, Prospect Requests] note: SOC reports and assurance documentation are provided to clients and prospects on request. evidence: - source: https://www.kraken.tech/legal/trust-center status: 200 date: '2026-07-27' keywords: [trust center, iso/iec 27001:2022, soc 1 type 2, soc 2 type 2, pci dss, gdpr, aes-256, tls 1.2, saml, dpo, subprocessors] probes_that_missed: - {host: trust.kraken.tech, dns: NXDOMAIN} - {host: security.kraken.tech, dns: NXDOMAIN} - {url: 'https://www.kraken.tech/legal/security', status: 200, note: 'legal links only — no certifications; the substance is at /legal/trust-center'}