Everything your ITreview will ask for.

Six policies, written to answer a HECVAT truthfully. Where a control does not exist yet, the document says so instead of implying it does.

Your records never reach our servers.
That is the architecture, not a promise about our uptime.

The policies

Six documents, written for a security reviewer.

Each one describes what Kenii actually does today. Send any of them straight to the person running your vendor assessment.

Information Security Policy

What Kenii secures, the standing rules enforced in code review, change control, patching, and how secrets are held. Ends by naming the limits of a small company rather than implying a security office exists.

Read the policy

Data Privacy Policy

Where institutional data lives, what the product holds, and a full table of every outbound request the software makes from your server, so your team can review or block any of them.

Read the policy

Incident Response and Breach Notification

How to report a security issue, the six steps that follow, and the notification clock by severity. Every institution running an affected version is told, not only the one that reported it.

Read the policy

Business Continuity and Disaster Recovery

What keeps running if Kenii goes dark, the 30-day offline license grace, who owns backups, and an honest statement of key-person risk.

Read the policy

Personnel, Access and Lifecycle

Who can reach your site, what they sign first, how access is limited, and the same-day checklist when someone leaves.

Read the policy

Third Parties and Subprocessors

Every third party the product calls, what each receives, and which are optional. Google Fonts and video embeds are named specifically because both send a visitor request off your domain.

Read the policy
What we do not claim

The controls we do not have yet.

A vendor questionnaire is easy to answer optimistically. These are the places Kenii answers no today, listed here rather than buried inside a document.

The continuity plan is untested

The recovery plan is written and the objective is stated, but it has not been tested end to end. The first test is scheduled and the result will be recorded on that page.

See the plan

Security training is not yet running

Annual security awareness training is defined and scheduled, but it is not operating and no completion has been recorded.

See the policy

No formal third-party assessments

Kenii reviews what data a provider would receive before adopting it, but does not run formal security assessments or hold negotiated breach-liability terms with each provider.

See the policy

No multi-state background screening

Not run as standard. Where a contract requires it for personnel touching your environment, screening is arranged for the named individuals as a condition of that contract.

See the policy

Hand these toyour reviewer.

If your assessment needs something these do not cover, ask. We will tell you whether we do it, rather than answering yes and working it out later.