Security at Kayaan
Kayaan handles load, carrier, and customer data for freight brokers. Security isn't a feature — it's the foundation. Here's how we protect it.
Encryption
All traffic to and from Kayaan is encrypted in transit with TLS 1.2 or higher. Customer data at rest is encrypted using AES-256. Keys are rotated on a regular schedule and managed through a cloud provider KMS.
Access control
- Role-based access control (RBAC) with least-privilege defaults
- Single sign-on (SSO) via SAML or OIDC for enterprise plans
- Multi-factor authentication required for all admin operations
- Full audit log of read and write events, available to customer admins
Infrastructure
Kayaan runs on SOC 2-certified cloud infrastructure in US regions. Production access is limited to a small set of engineers, requires MFA, and is fully logged. We run continuous vulnerability scanning and review dependencies weekly.
Data handling
Customer data is logically isolated by tenant. Load, carrier, and driver PII is only used to operate the platform on behalf of the customer. See the Privacy Policy and DPA for details.
Compliance
- SOC 2 Type II — in progress
- FMCSA and DOT regulatory alignment for broker operations
- GDPR and CCPA — processor obligations covered in the DPA
Responsible disclosure
Found a security issue? Email support@kayaan.ai. We publish a machine-readable contact at /.well-known/security.txt. We do not currently run a public bounty program but we recognize and credit responsible disclosures.
