Rely on advanced security & compliance standards to automate your pricing process

Customer trust and data security is of the utmost importance to Akur8. We are committed to protecting your data by adopting the highest security standards.
Afaq iso27001 logo
FSQS logo
AICPA SOC2 logo
ISO 27001-certified

Your information is safe with best-in-class information security standards

Akur8 meets all requirements for establishing, implementing, maintaining and continually improving an efficient information security management system, as required by the ISO 27001 standards. Akur8 systematically examines information security risks and maintains a comprehensive suite of controls to address those risks, with a solid and constantly reinforced management process to ensure controls are up-to-date on an ongoing basis.

Holds SOC2 Type II report

Your customer data
is in good hands

The completed SOC2 Type II compliance confirms Akur8 commitment to continually ensuring higher standards and assessing data security measures for effectiveness. The SOC2 report outlines the extensive security, availability and confidentiality measures, implemented and maintained by Akur8 to meet both internal and customer expectations for security controls.

Cloud computing

Rely on the leading cloud-computing service provider to model with confidence

Akur8 uses AWS as our cloud-computing service provider. The highest security standards and the most robust controls are in place at AWS to ensure safety and data protection. The IT infrastructure that AWS provides to Akur8 is designed and managed in alignment with the most demanding security practices and a variety of industry recognised security standards. The following is a partial list of assurance programs with which AWS complies:

  • SOC 2 Type II,
  • ISO 27001, ISO 27017, ISO 27018,
  • PCI-DSS,
  • Fedramp.
Data security

Your data is safe with a platform secured by design

Security has been integrated from the beginning in the design and the development of the Akur8 platform to ensure the confidentiality, integrity and availability of your data.

Confidentiality

We implement a variety of controls to ensure your data remains confidential and is accessed only by authorized persons. These controls include, but are not limited to: absolute segregation between customers, the encryption of data with state of the art algorithms, strict access controls and regular penetration tests by an independent third party.

Integrity

We deploy a variety of controls to ensure that your data is protected against unauthorized alterations, such as strict access controls, regular backups, regression tests in the change management process, audit trails, etc.

Availability

Our platform and your data are automatically replicated in several locations to ensure a high level of resilience and backups are performed on a daily basis.

Compliance Privacy Standards

At no time does Akur8 have access to personal data.
During every step of the data upload process, Akur8 reminds customers that personal data should not be uploaded unless anonymized.
However, in specific cases where the client has embedded personal data by default into the database, Akur8 ensures compliance with CCPA, GDPR, and national or federal privacy and data protection standards.

Frequently Asked Questions

Does Akur8 have a dedicated security team?

Yes. Akur8 has a dedicated security team led by a Chief Information Security Officer (CISO). The team is responsible for designing, implementing, and overseeing the information security program across all Akur8 products.

How does Akur8 develop code securely?

Akur8 follows a structured software development lifecycle (SDLC) that ensures code is rigorously tested, authorized, and approved before reaching production. Changes go through defined review and approval stages, including peer code review and security testing, to maintain the integrity and security of the platform.

Is data encrypted at rest and in transit?

Yes. Data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher. All communication sessions between the platform and end-users are secured via HTTPS.

Does Akur8 conduct penetration testing?

Yes. An independent third party performs an application-level penetration test at least once a year. The penetration test attestation letter is available on request through our Trust Center.

How does Akur8 monitor for vulnerabilities?

Vulnerability scans run at least monthly across public-facing components, internal systems, and code repositories. A SIEM collects and analyzes logs in real time, alerting the security team to suspicious patterns. Continuous threat detection monitors production environments for unauthorized or malicious activity.

How is access to systems and data managed?

Access follows a role-based model (RBAC) with least-privilege principles. Multi-factor authentication (MFA) is enforced for remote and production access. User access is reviewed biannually to confirm it remains appropriate.

What happens if there is a security incident?

Akur8 maintains a documented incident response plan with defined escalation paths based on severity. Affected customers and relevant stakeholders are notified without undue delay and in accordance with contractual obligations and applicable regulation.

How does Akur8 ensure platform availability?

Akur8 products are built on leading cloud providers engineered for high availability. Data and services are replicated across multiple availability zones, ensuring continuity in the event of a localized failure. Backups run daily. Failover procedures and restore-from-backup processes are tested regularly as part of our Business Continuity and Disaster Recovery (BC/DR) program, and infrastructure is monitored continuously.

Are Akur8 employees trained on security?

Yes. All employees complete mandatory security awareness training at onboarding and at least annually thereafter. Developers receive additional secure development training based on the OWASP Top 10.

How does Akur8 manage third-party and vendor risk?

Akur8 maintains a third-party risk management process. Vendors and contractors are subject to contractual confidentiality and security requirements. Third parties are reviewed periodically, with a review cadence based on criticality and risk profile.

Can I get a copy of the SOC 2 Type II report?

Yes. SOC 2 Type II reports are available through the Akur8 Trust Center. Request access here.

All FAQ
Get in touch with our team to learn more about the solution.
Contact us