Is this your company? Buyers are checking Kara Connect here. Claim karaconnect.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Claim free
Kara Connect
Sourced from public information. Not yet verified by the company.
Kara Connect is SOC 2 compliant. Kara Connect also holds ISO 27001, and GDPR.
About
Information security is a critical component of Kara Connect's success. Both professionals and clients must be confident that the system complies with laws and regulations and be assured of secure communications. From the beginning, our team has significantly focused on security measures, ensuring that Kara Connect meets all the requirements set by Iceland's National Directorate of Health for Telehealth Services. Additionally, Kara Connect has achieved a significant milestone in its commitment to maintaining high information security standards by successfully achieving the ISO 27001 certificat
Compliance & infrastructure
Documents
10Subprocessors
15- AAmazon Web Services · Infrastructure Hosting
- LLivekit · Video room management
- MMailjet · Email notifications
- HHubSpot · Marketing CRM Integration
- AAtlassian · Engineering and Development
- JJira · Collaboration
- PPostHog · Data analytics
- TTwilio · Notifications (EU)
- GGoogle Workspace · Email Google Suite
- SSlack · Internal Communications and Notifications
- GGoogle Analytics · Data analytics
- SSentry · Application monitoring
Show all 15 subprocessorsShow fewer
- SStripe · Finance and payments
- XXero · Finance and payments
- DDocuSign · Electronic Signatures
Compliance leadership
The person who leads Kara Connect's SOC 2 isn't listed yet. Claim this profile to add it.
Penetration test
Unknown. Kara Connect's penetration test vendor isn't listed yet.
Claim this profile to add it.
Recent updates
Kara Connect Successfully Completes Annual ISO 27001 External AuditFeb 2025
We are pleased to announce that Kara Connect has successfully completed its annual ISO/IEC 27001:2022 external audit, reaffirming our commitment to the highest standards of information security and continuous compliance. ISO/IEC 27001 is the internationally recognised standard for information security management systems (ISMS). Our successful audit completion demonstrates our dedication to protecting customer data, maintaining strong security controls, and ensuring operational resilience. #### What This Means for Our Customers - Independent Verification: Our security practices have been externally audited and remain in compliance with ISO 27001 requirements. - Ongoing Commitment to Security: We continuously assess and improve our security controls to meet evolving cybersecurity challenges. - Data Protection & Trust: Your sensitive data remains safeguarded through industry-leading security policies and controls. For more details about our security and compliance efforts, visit the Kara Connect Trust Center or contact us at security@karaconnect.com.
New Certification Announcement: NordDEC CertificateNov 2024
We are proud to announce that Kara Connect was recently recognized as a top 3 finalist in the prestigious Nordic Health App Awards, a testament to our dedication to innovation and excellence in the digital health sector. As part of this achievement, we have been awarded the NordDEC certificate, which underscores our commitment to maintaining high standards in digital health solutions. The NordDEC certification is a mark of trust and quality, awarded to companies that meet rigorous criteria for data security, compliance, and user safety within the healthcare technology landscape. This recognition reflects our continuous efforts to uphold best practices in the development and management of our health app, ensuring that user data is safeguarded and handled with the utmost care. We are honored to add the NordDEC certification to our credentials and remain dedicated to advancing secure, reliable, and effective digital health solutions for all our users.
Kara Connect ISO 27001 CertificationJan 2024
The successful completion of this phase and the subsequent awarding of the certification demonstrate Kara Connect's adherence to some of the most stringent criteria for managing sensitive company and customer information. The process involved a comprehensive review of the company's data protection practices, risk management procedures, and IT infrastructure. The certification also indicates that Kara Connect has adequate controls and policies to identify, manage, and reduce risks to information security. This achievement is a testament to the company's current security practices and lays a solid foundation for its ongoing commitment to data security. It ensures that clients and partners can trust Kara Connect with the secure handling of their information as the company continues to uphold and improve upon these high data protection and security management standards in the future.
This listing is partial
7/11 details · 64%SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
- Auditorraises trustAdd the CPA firm that issued your SOC 2 so buyers can verify who signed it.
- Report dateraises trustAdd your most recent report period so buyers see how current your SOC 2 is.
- Renewal dateAdd your renewal window so buyers know your coverage is active.
- Security controlsConfirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Kara Connect SOC 2 compliant?
Is Kara Connect ISO 27001 certified?
Is Kara Connect GDPR compliant?
Can I use Kara Connect's SOC 2 for a vendor risk assessment?
Is Kara Connect penetration tested?
Does Kara Connect have an ISO 27001 certificate?
Is Kara Connect secure?
Does Kara Connect have a bug bounty or vulnerability disclosure program?
Who are Kara Connect's subprocessors?
Where does Kara Connect host or store data?
Where is Kara Connect's trust center or security page?
Does Kara Connect feature a three-tier architecture?
Is Kara Connect’s data encrypted?
Where are our data centers located and what is the robustness of data centers and access channels?
What standards/methods are used for securing data transmission, data storage, data transformation, data segregation and user access?
Does Kara Connect use any OAuth 2.0 Access Controls?
Have the solution components and virtual servers been configured and hardened in line with cyber security standards, such as CIS?
Are components/virtual servers monitored for vulnerabilities and updated in a timely manner when discovered?
Are developer and operator workstations and servers used in the hosting operations set up with AV and monitoring agents?
Is multifactor authentication (2FA/MFA) enforced for developers, administrators and others who have access to hosting platform/components, databases, virtual machines administrative/management portals, SSH sessions and alike?
Are all communications enforced to use TLS 1.2 or later?
Are there separate development, testing and production systems set up for the application?
How are system and data segmented between the application service providers and end users?
Healthcare peers that completed SOC 2
Vitablehealth

Elfie

ThoughtFull World
