Komo recognises that the confidentiality, integrity and availability of information and data created, maintained and hosted by us are vital to the success of the business and privacy of our partners.
As a service provider/product, we understand the importance in providing clear information about our security practices, tools, resources and responsibilities within Komo so that our customers can feel confident in choosing us as a trusted provider.
This Security Posture highlights high-level details about our steps to identify and mitigate risks, implement best practices, and continuously develop ways to improve.
Founded in 2014
Here are the controls implemented at Komo to ensure compliance, as a part of our security program.
Situational Awareness For Incidents
Identify Validation
Termination of Employment
Encrypting Data At Rest
Inventory of Infrastructure Assets
Data Backups
Testing for Reliability and Integrity
Transfer of PII
External System Connections
Anomalous Behavior
Data used in Testing
Conspicuous Link To Privacy Notice
Approval of Changes
Code of Business Conduct
Organizational Structure
Roles & Responsibilities
Competency Screening
Personnel Screening
New Hire Policy Acknowledgement
Security & Privacy Awareness
Performance Review
Periodic Policy Acknowledgement
Automated Reporting
Incident Reporting Assistance
Risk Framing
Risk Assessment
Fraud
Third-Party Criticality Assessments
Assigned Cybersecurity & Privacy Responsibilities
Internal Audit using Sprinto
Periodic Review & Update of Cybersecurity & Privacy Program
Subservice organization evaluation
Segregates Roles and Responsibilities
Subprocessor Requirements
Data Protection Impact Assessment (DPIA)
EU Representative
Testing
Customer Obligations
Chief Privacy Officer (CPO)
Privacy Act Statements
Asset Ownership Assignment
Infosec training ack
Data Governance
New Hire Security & Privacy Training Records
Periodic Security & Privacy Training Records
Updates During Installations / Removals