Skip to content
Access Kaiseki Access Kaiseki

I Access Kaiseki · Colophon

The SOC 2 Type II report is continuously audited and available on request under NDA.

Access Kaiseki has held a public SOC 2 Type II report since 2020, renewed annually by Schellman & Co. The same tenant carries ISO 27001, FedRAMP Moderate, and HIPAA attestations — verified, not self-asserted. This page is the document a CISO opens in a second tab during evaluation.

Request the SOC 2 report

Report renewed continuously since 2020 · Single-tenant attestations · Schellman & Co., independent auditor

II Certifications index

Four attestations, one tenant, one continuous audit cycle.

Every certification below is held by the same Access Kaiseki production tenant — the one your data lands in. No audit-of-audit, no separate staging scope.

  1. I

    SOC 2 Type II

    Trust Services Criteria for Security, Availability, and Confidentiality. Continuous annual audit by Schellman & Co. Report renewed without lapse since 2020.

    Auditor · Schellman & Co., LLC
    Latest attestation · 2024
    Cadence · Continuous (12-month look-back)

  2. II

    ISO/IEC 27001:2022

    Information Security Management System certified across engineering, infrastructure, and customer operations. Statement of Applicability covers 93 Annex A controls.

    Certifying body · Schellman & Co., LLC
    Certificate issued · 2023
    Valid through · 2026

  3. III

    FedRAMP Moderate

    Authorized at the Moderate baseline for use by U.S. federal agencies and their contractors. 3PAO assessment covers 325 controls from NIST 800-53 Rev. 5.

    3PAO · Schellman & Co., LLC
    Authorization · 2024
    Baseline · Moderate (not High)

  4. IV

    HIPAA

    Type 1 attestation against the HIPAA Security Rule. Covers administrative, physical, and technical safeguards for Protected Health Information handled under BAA.

    Attestor · Schellman & Co., LLC
    Latest report · 2024
    Coverage · Security Rule §164.308–§164.312

III Auditor's note

A continuous engagement, not an annual snapshot.

"Schellman & Co. has served as Access Kaiseki's independent service auditor since 2020. Our engagement operates on a continuous basis: controls are tested throughout the audit period rather than at year-end, and findings are remediated inside the same window they are identified. The reports we issue — SOC 2 Type II, ISO 27001, FedRAMP Moderate, and HIPAA — are scoped to the same production tenant and the same control library, which is unusual for an IGA vendor of this size and gives security evaluators a single, consistent evidentiary surface."

Schellman & Co., LLC

Independent service auditor · ISO/IEC 27001 certification body · FedRAMP 3PAO

IV Trust metrics

What the numbers say, without the marketing.

99.995%

Published availability SLA

Enterprise tier · measured monthly · credits issued automatically when the SLA is missed.

4×

Faster SOC 2 & ISO 27001 audits

Median cycle time reduction across 1,800+ deployments studied in the Forrester TEI report (Q3 2024).

1,800+

Deployments in the TEI study

Forrester Total Economic Impact, Q3 2024 · 71% average reduction in access-review cycle time.

0

Downtime upgrades since 2021

Rolling, in-place upgrades · change windows are customer-visible in the status page · no maintenance blackouts.

V Sub-processors & contact

Who we share customer data with, and who answers your questionnaire.

Sub-processor inventory

Access Kaiseki shares customer data only with the sub-processors listed below. Notification of changes is sent 30 days in advance via the in-product trust center.

Cloud hosting
Amazon Web Services · US-East, US-West, EU-Frankfurt, AP-Sydney regions · data at rest encrypted with KMS-managed keys.
Observability
Datadog · application logs and metrics · 30-day retention · no customer payloads included in log streams.
Support tooling
Zendesk · ticketing and customer correspondence · SOC 2 Type II attested · EU data residency available.
Email delivery
Postmark · transactional email for access requests, approvals, and MFA challenges · no marketing email routed through customer data.
Error tracking
Sentry · anonymized stack traces · PII redaction enforced at the SDK level before transmission.

Compliance contact

Send RFPs, CAIQ questionnaires, and security review packets directly. Median first response: one business day.

Trust & compliance
[email protected]
Vulnerability disclosure
[email protected]
Privacy & DPIA requests
[email protected]
Security.txt
Published at /.well-known/security.txt · signed PGP key · 90-day disclosure SLA.
Headquarters
535 Mission Street, 14th Floor
San Francisco, CA 94105, USA
+1 (415) 555-0182

VI Request the dossier

Request the SOC 2 Type II report and the ISO 27001 certificate under NDA.

Both documents are delivered within one business day of a countersigned mutual NDA. The report covers the trailing 12 months of continuous testing by Schellman & Co. and includes the bridge letter for any gap to today.

Request the SOC 2 report

No marketing follow-up · Routed directly to the trust & compliance team