
Security your risk team can review
Kenal runs identity, documents and filings for regulated institutions, so we run the company the way your vendor-risk review expects: written policies, independent testing, a choice of where it runs, and the evidence shared under NDA.
Security pack, shared under NDA
- Information security policy
- Incident response and business continuity plans
- AI governance framework
- Penetration test and VAPT summaries
- AML and PEP data sources
- Hosting, residency and keys for your products
Controls we operate as a company
Each is a written company policy or an independent test report. Customers and prospective customers can review them under NDA.
We do not claim certifications we do not hold.
Information security policy
One company-wide policy covering data classification, access control, network security, encryption, vulnerability management and audit logging.
Cybersecurity incident response plan
How we detect, contain, investigate and recover from an incident, who owns each step, and how and when affected clients are told.
Business continuity management plan
How we keep services running, and restore them, when systems, suppliers or people are unavailable, with recovery objectives and regular testing.
AI governance framework
How we build, test, monitor and oversee the models behind our products, with human review wherever a decision needs it.
Independent penetration testing of Kenal eKYC
Third-party testing of Kenal eKYC's apps and APIs, with the findings and how each one was fixed.
Vulnerability assessment and penetration test of Kenal Stamps
A VAPT of Kenal Stamps, the platform and its automation, with the remediation record.
Documented AML and PEP data sources
Where our sanctions, PEP and adverse-media screening data comes from, listed source by source, so your compliance team can assess coverage.
Run it where your policy says it must run
Kenal products are delivered three ways. We confirm which apply to each product when we scope your deployment.
SaaS
We host, run, patch and monitor the service. The fastest way to go live.
Your cloud
Deployed into your own cloud account, inside your network, under your security controls and your keys.
On-premise
Installed in your own data centre for workloads that must stay on infrastructure you operate.
PDPA-aligned data protection
We handle personal data in line with Malaysia’s Personal Data Protection Act 2010, collect only what a workflow needs and act on our clients’ instructions. Our privacy policy explains what we collect and why. Questions go to privacy@kenal.io.
Availability
Our SLAs target 99.9% availability; commitments are set per product. Support hours and response times are agreed in your contract.
Residency, hosting and keys
These are set per product. Kenal Aura and Kenal Stamps publish theirs; for every other product, they are in the security pack.
Responsible disclosure
Found a vulnerability in a Kenal product or website? Email security@kenal.io with what you found and the steps to reproduce it.
We acknowledge every report and keep you informed while we fix it. Please give us reasonable time before you disclose it publicly, and do not access, change or keep data that is not yours.
Security questions buyers ask
What security assurance can Kenal provide?
Kenal operates documented company-level controls: an information security policy, an incident response plan, a business continuity plan, an AI governance framework and independent penetration testing. We do not claim certifications we do not hold. Customers and prospective customers can review every one of these documents under NDA by requesting our security pack.
How do we get Kenal's security documents for a vendor-risk review?
Request our security pack through the contact form or by emailing security@kenal.io. Tell us which Kenal products you are reviewing and we will send the relevant policies, plans, test summaries and hosting details under NDA. Most reviews need nothing more, and our team will answer your questionnaire or join a call with your security team when they do.
Can Kenal run in our own cloud or on-premise?
Yes. Kenal products can be delivered as SaaS, deployed into your own cloud account, or installed on-premise in your data centre. Running in your environment keeps the data inside your network and under your controls and keys. Which options apply depends on the product, and we confirm them when we scope your deployment.
Where is our data hosted, and who holds the keys?
Hosting region, data residency and key management are set per product and per deployment. Kenal Aura and Kenal Stamps publish theirs on their own security pages. For every other product the details are in the security pack, and a your-cloud or on-premise deployment puts hosting and keys under your control.
How does Kenal protect personal data under the PDPA?
Kenal handles personal data in line with Malaysia's Personal Data Protection Act 2010. We collect only what a workflow needs, protect it with access controls and encryption, and act on our clients' instructions as their data processor. Our privacy policy explains what we collect and why, and privacy@kenal.io reaches the person responsible for data protection.
What availability does Kenal commit to?
Our SLAs target 99.9% availability; commitments are set per product. The exact service levels, support hours and response times are agreed in your contract for each product you use. Our business continuity plan sets out how we keep services running and restore them when systems or suppliers fail, and it is part of the security pack.
How do we report a security vulnerability in Kenal?
Email security@kenal.io with a description of the issue and the steps to reproduce it. We acknowledge reports, investigate them and keep the reporter informed while we fix the issue. Please give us reasonable time to resolve it before you disclose it publicly, and do not access, change or keep data that does not belong to you.
Request our security pack
Tell us which Kenal products you are reviewing and we will send the relevant documents under NDA.