Skip to main content
Kernel’s compliance artifacts live in the trust center: trust.kernel.sh. What you’ll find there:
  • The SOC 2 Type II report, available on request.
  • Current compliance status.
  • The authorized subprocessor list, referenced by the DPA.
  • Security artifacts and questionnaire responses for vendor review.
For how the program works rather than the paperwork, see security practices and the shared responsibility model. For what changes on an Enterprise plan — BAA and zero data retention — see Enterprise. Security questions go to security@kernel.sh. Reporting a vulnerability? See vulnerability reporting.