Kapintelligence combines tenant controls, EU-hosted processing, role-based access and source-linked outputs for regulated institutional workflows.
We state controls we can evidence rather than absolutes. Source traceability is not the same as complete system auditability, and tenant architecture is a technical question with a technical answer - both are documented in the security pack, with scope and dates.
Select a stage to see where data sits, which controls apply and what your security team should verify during procurement.
Kapintelligence is operated in accordance with the EU General Data Protection Regulation (GDPR / DSGVO). Personal data is processed on the customer's instruction under a data processing agreement (Auftragsverarbeitungsvertrag, Art. 28 GDPR), with processing and storage in EU regions. For customers in Germany, the German Federal Data Protection Act (BDSG) applies alongside the GDPR.
Beyond data protection, Kapintelligence provides controls that can support customer obligations under relevant operational-resilience and investment-governance frameworks.
Applicability and compliance remain customer-specific. Detailed control mapping is available during procurement. We do not describe the platform as compliant with a regulation on your behalf.
We publish a certification only once it has been issued, with its scope and date. Until then we share the programme status, the scope under assessment and the current penetration-test and control evidence.
No badge on this site represents a certification that has not been issued. Ask for the current status in writing and it will be in the security pack.
Sent to named security, risk and IT contacts, with a working session if your review requires one.
Qualified request: we ask for your role and organisation so the right documents and the right people are involved.
We answer it against the current architecture and contracts, in writing, with named owners.