SOC2C

Kernel security & compliance

An overview of Kernel's security posture — compliance, penetration testing, subprocessors, and data handling — verified on SOC2C (Listed).

SOC 2 statusSOC 2 Type II · Listed
FrameworksSOC 2 Type II
Penetration testNot listed
Subprocessors11 listed
HostingAWS, GCP, Azure
Trust centerView

Security questions about Kernel

Is Kernel secure?
Security isn't a single yes/no, but Kernel is SOC 2 Type II compliant. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Kernel have a bug bounty or vulnerability disclosure program?
Kernel hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@kernel.ai or via a /security page (Kernel lists a security contact).
Who are Kernel's subprocessors?
Kernel lists 11 subprocessors on its trust center, including AWS, Google Workspace, Vanta, Google Cloud Platform, Slack. Buyers use this for fourth-party risk review.
Where does Kernel host or store data?
Kernel hosts on AWS, GCP, Azure, and handles Customer personally identifiable information, Employee personally identifiable information, Credit card information, Personal health information. Data residency details are on its trust center.
Where is Kernel's trust center or security page?
Kernel's trust center is at https://trust.kernel.ai. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.

See Kernel's full SOC 2 profile →