Kapintelligence security and data protection
Security and trust

Sensitive investment data, isolated by design and reviewable to source.

Kapintelligence combines tenant controls, EU-hosted processing, role-based access and source-linked outputs for regulated institutional workflows.

{{ h }}
Request the security pack Book a security review

We state controls we can evidence rather than absolutes. Source traceability is not the same as complete system auditability, and tenant architecture is a technical question with a technical answer - both are documented in the security pack, with scope and dates.

Architecture

Follow a document through the system.

Select a stage to see where data sits, which controls apply and what your security team should verify during procurement.

Stage {{ zone.num }} ยท {{ zone.region }}

{{ zone.name }}

{{ zone.teaser }}

{{ zone.detail }}

{{ c }}
Verify with us
{{ v }}

Each item is answered with a document, a configuration screenshot or a contract clause - not a claim on a website.

Trust architecture

Eight domains, each answered explicitly.

{{ d.domain }}
{{ d.explicit }}
Regulatory framing

Designed to support regulated European investment workflows.

Kapintelligence is operated in accordance with the EU General Data Protection Regulation (GDPR / DSGVO). Personal data is processed on the customer's instruction under a data processing agreement (Auftragsverarbeitungsvertrag, Art. 28 GDPR), with processing and storage in EU regions. For customers in Germany, the German Federal Data Protection Act (BDSG) applies alongside the GDPR.

Beyond data protection, Kapintelligence provides controls that can support customer obligations under relevant operational-resilience and investment-governance frameworks.

Applicability and compliance remain customer-specific. Detailed control mapping is available during procurement. We do not describe the platform as compliant with a regulation on your behalf.

Certification status

Stated plainly, never implied.

We publish a certification only once it has been issued, with its scope and date. Until then we share the programme status, the scope under assessment and the current penetration-test and control evidence.

No badge on this site represents a certification that has not been issued. Ask for the current status in writing and it will be in the security pack.

Procurement

The security pack, in one request.

Sent to named security, risk and IT contacts, with a working session if your review requires one.

Request the security pack

Qualified request: we ask for your role and organisation so the right documents and the right people are involved.

{{ p }}

Security questions we get asked

{{ f.a }}

Bring your security questionnaire.

We answer it against the current architecture and contracts, in writing, with named owners.

Book a security review
See the platform architecture