Data security and compliance are core to us
Kombo's platform is built with security at its core, ensuring your customers' data remains protected at all times.
Designed for enterprise data protection needs
Customer trust and data security are critical to us. Kombo provides comprehensive security controls and compliance frameworks specifically built for the regulatory requirements and data sensitivity of HR tech integrations.
Compliant with security and privacy standards
Built-in security controls and industry-standard certifications protect your customers' data. Kombo complies with SOC 2 Type 2, HIPAA, GDPR, and is also ISO 27001 certified.
Enterprise security needs
Data minimization
Accountability and compliance
How does Kombo protect and secure data?
All data is encrypted using industry-standard algorithms. Data is encrypted using AES-256 at rest, and using Transport Layer Security (TLS) in transit.
Where are Kombo's Servers located?
Data is stored regionally depending on where your partner is operating:
• For the US, data is stored in Google Cloud Centers in the US.
• For the EU, data is stored in Google Cloud Centers in the Netherlands.
Why do you require employee data?
Some employee data will be required for the service of your partner to function. For example, a spend management service will require access to bank account data (like IBAN) to enable automatic reimbursements.
Kombo empowers services to stay compliant by enabling them to limit data access to only what's necessary for their functionality. The legal basis of the exchange of data is always the contract between you and the service.
What if not all employees are relevant to the service?
When connecting their HRIS via Kombo, your customers are able to set filters that define which employees will be read. Only employees matching these filters will be exposed to your solution.
Why do you require applicant data?
Some applicant data will be required for the service of your partner to function. For example, a background check provider will require access to candidate information (like name and email) to initiate screening processes, or an assessment tool will need application details to send evaluation links to candidates.
Kombo empowers services to stay compliant by enabling them to limit data access to only what's necessary for their functionality. The legal basis of the exchange of data is always the contract between you and the service.