This page summarizes security controls that are represented in the current application configuration. It is a transparency page, not a claim of a third-party certification or audit.
Reviewed August 27, 2026
The application applies additional protections to onboarding and invite routes that may contain bearer-style tokens. Current configuration uses private/no-store caching, no-referrer behavior, and noindex/nofollow/noarchive directives for those sensitive paths.
This page does not state that Kelvaro has completed SOC 2, ISO 27001, PCI DSS, or another third-party certification unless a separate current statement explicitly documents that status.
Security controls evolve with the product. The reviewed date on this page indicates when the public description was last checked against the application configuration.