Krank
Enterprise-grade security

EmbeddedInfrastructureSecurity

Secure and scalable infrastructure embedded within a connected operational ecosystem. Get intelligent control and reliability for your most critical assets.

ISO 27001GDPR Compliant

1. ISO 27001 Certified & UK GDPR Compliant

Krank maintains an ISO/IEC 27001-certified Information Security Management System (ISMS) and operates in compliance with the UK General Data Protection Regulation (UK GDPR). Our information security controls are independently audited, and certification details can be provided upon request. Personal data is processed lawfully, transparently, and in accordance with applicable data protection legislation, with mechanisms in place to support individuals' rights to access, rectify, and request the deletion of their personal information.

2. Secure Infrastructure

Krank's platform is hosted on Amazon Web Services (AWS), leveraging a highly resilient and secure cloud infrastructure. AWS maintains internationally recognised security certifications and attestations, including ISO/IEC 27001, SOC 2, PCI DSS Level 1, and FISMA Moderate, providing a strong foundation for the security, availability, and resilience of our services.

3. Data Encryption

All data transmitted between users and the platform is protected using industry-standard TLS encryption. Sensitive data stored within the platform is encrypted at rest using strong AES encryption. User passwords are securely hashed using modern cryptographic algorithms and are never stored or transmitted in plain text.

4. Vulnerability Scanning & Patching

Krank operates a continuous vulnerability management process to identify, assess, and remediate security vulnerabilities. Security patches for operating systems, applications, third-party components, and supporting infrastructure are applied in accordance with defined risk-based Service Level Agreements (SLAs).

5. Penetration Testing

The platform undergoes periodic independent penetration testing by qualified third-party security specialists. Identified findings are assessed, prioritised according to risk, and remediated through a structured vulnerability management process.

6. Application Access

Access to customer data is governed by a Role-Based Access Control (RBAC) model, ensuring users are granted only the minimum level of access required to perform their authorised responsibilities. Data segregation mechanisms ensure organisations can access only their own information.

7. Access Control

Access to production environments is restricted to authorised personnel and protected through Multi-Factor Authentication (MFA) and the principle of least privilege. Access to customer data is strictly controlled, logged, and limited to authorised support or operational activities where there is a legitimate business need.

8. Security Training

All employees receive regular information security awareness training covering cybersecurity best practices, secure handling of information, phishing awareness, password security, social engineering, and other common cyber threats. Training is refreshed periodically to maintain awareness of evolving risks.

9. Disclosure

Krank is committed to maintaining the security of its platform and services. If you believe you have identified a security vulnerability, please report it responsibly to security@krank.com. All reports are reviewed promptly, investigated appropriately, and handled in accordance with our vulnerability disclosure process.