# SOC 2, GDPR, and the Trust Center

Find Kastra's vendor assurance material and connect it to your security and privacy review.

Updated: 2026-09-22

Canonical: https://docs.kastra.ai/security/assurance

## Start with Kastra's Trust Center

Use the [Kastra Trust Center on Oneleet](https://trust.oneleet.com/kastra) to review SOC 2 assurance and GDPR documentation for your vendor assessment. Check the stated status, document scope, and access requirements there. If your review needs material that is not visible, [contact Kastra](https://kastra.ai/contact) with the document or question you need resolved.

The Trust Center is the reference for Kastra's security and privacy assurance. These product guides explain how the integrations behave and how your team can evaluate them.

## Review the SOC 2 evidence

For the applicable report, check the legal entity and system covered, report type, reporting date or period, trust services categories, auditor's opinion, exceptions, and relevant customer responsibilities. Confirm how the scope applies to the service and deployment you plan to use.

SOC 2 is an assurance examination and report. A product's ability to export framework-mapped evidence is separate from that vendor assurance. AICPA provides the [SOC 2 overview](https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2/) and [report review checklist](https://assets.ctfassets.net/rb9cdnjh59cm/3xbcLlNc5rd72So4nQpNIk/7a3e8e5945c78c35fc5e116859b96e6a/SOC_2_Report_%C3%82_Review_Checklist.pdf).

## Review the GDPR documentation

Assess the processing relationship for your use case, the applicable data processing terms, technical and organizational measures, subprocessors, locations and transfer arrangements, retention/deletion, and the handling of privacy requests. Match those documents to the data paths and optional features you will enable.

GDPR compliance involves ongoing obligations for the relevant parties and processing. A completed readiness review is a starting point for maintaining that program; it is not a universal product certification or approval for every customer use. The European Commission's [GDPR guidance](https://commission.europa.eu/law/law-topic/data-protection/information-business-and-organisations/obligations_en) explains the wider obligations.

## Request a focused vendor review

| Review area | Material or answer to request |
| --- | --- |
| Assurance scope | Applicable SOC 2 report, scope, period, and any relevant coverage update |
| Privacy | Applicable DPA, subprocessor information, data locations, retention, deletion, and privacy contact |
| Security operations | Relevant security-control and vulnerability-management information for the proposed service |
| Deployment | Supported architecture, customer responsibilities, upgrade process, and access boundaries |
| Commercial continuity | Agreed support, incident communication, availability terms, and exit/data-handling process |

This is a review request list; access to a particular document and its applicability should be confirmed through the Trust Center or the Kastra team.

## Combine assurance with a product evaluation

Vendor assurance supports supplier due diligence. Your [pilot results](https://docs.kastra.ai/security/evaluation) establish integration behavior, and [decision evidence](https://docs.kastra.ai/evidence/exports) supports ongoing reviews of connected actions. Keep all three scopes explicit in your approval record.

[Open the Trust Center](https://trust.oneleet.com/kastra) · [Review data protection](https://docs.kastra.ai/security/data-protection) · [Contact Kastra](https://kastra.ai/contact)
