// security & trust

Evidence you can review. Controls you can verify.

Kotav Labs delivers authorised security assessments through a controlled engagement model. This page states what we protect, how delivery is governed and where our boundaries are.

KOTAV / TRUST CENTER
Authorised testing
EU-hosted evidence
Reviewed delivery
Tenant separation
// operating safeguards

Security built into the delivery model.

They apply from written authorisation through to reviewed evidence and traceable delivery.

01

Authorised testing

Testing starts only after scope, hosts, dates, rate limits, write permissions and Rules of Engagement are documented.

02

EU-hosted evidence

Assessment infrastructure and evidence are hosted in Germany. Subprocessors and any additional processing locations are disclosed per engagement.

03

Reviewed delivery

Material findings receive specialist review. Deliverables use verified evidence and an audit-suitable report, with PDF and SARIF where applicable.

04

Tenant separation

Tenant-scoped access, explicit roles and server-side authorisation protect customer records and operational actions.

05

Account security

HttpOnly sessions, rotating refresh tokens, TOTP MFA, one-time backup codes and encrypted secrets protect browser accounts.

06

Traceability

Assessment jobs, finding changes, retest requests, role changes and sensitive administrative actions produce attributable records.

// scope of service

Clear operational boundaries

Argus Sentinel provides passive intelligence and correlation between assessments. Round-the-clock monitoring and incident response sit outside this service, while certification depends on an independent assessment. Retention, subprocessors, testing permissions and deliverables are agreed for each engagement.

// due diligence

Security review material

A DPA, security FAQ, subprocessor disclosure, sample deliverables and technical answers are available during qualification under appropriate confidentiality terms.

// assurance register

Assurance status and scope.

Each item below states its current scope and status. We identify operating safeguards, voluntary commitments, self-assessments and independent certification separately.

Last reviewed 5 September 2026

01

CREST AI Charter

Commitment submitted

Kotav Labs submitted its commitment to the nine CREST AI Principles on 5 September 2026. Public listing and the badge remain pending.

CREST principles
02

CSA AI Trustworthy Pledge

Pledge submitted

Kotav Labs submitted all four AI Trustworthy Pledge principles on 5 September 2026. CSA confirmed receipt; public listing and the digital badge remain pending.

CSA pledge
03

CSA STAR Level 1

Questionnaire complete

All 283 CAIQ v4.1 questions are answered for the defined customer-facing service boundary. Registry submission and CSA publication confirmation remain outstanding.

CSA STAR
04

CSA STAR for AI Level 1

Questionnaire complete

All 320 AI-CAIQ v1.1 questions are answered for Argus model use, Rogue verification and the supporting control plane. Registry submission and CSA confirmation remain outstanding.

STAR for AI
05

NIST CSF 2.0 and AI RMF

Frameworks in use

Scoped current and target profiles structure our internal improvement programme, with evidence reviews tracked against each profile.

NIST CSF
06

OWASP ASVS 5.0 and SAMM

Methodology adopted

Assessment and development practices reference selected OWASP requirements and retain review evidence.

OWASP ASVS
07

NIS2

Internal implementation complete

Our scoped internal NIS2 programme has complete control, operating-evidence and management-approval records across governance, risk management, incident handling, continuity, supply-chain security, secure development, cryptography, access control and disclosure. These safeguards remain under continuous review. Applicability and any registration or reporting duties remain subject to the competent authority.

EU NIS2 overview
08

ISO/IEC 27001:2022

ISMS programme active

Policies, risk records, control ownership and operating evidence form an active ISMS programme.

ISO certification guidance
// what supports a claim

What supports each status.

A policy alone does not prove operation. Public claims require a defined scope, an accountable owner, dated evidence and a recorded review.

01
Authorisation, scope and Rules of Engagement
02
Execution and intervention logs
03
Evidence provenance and specialist decisions
04
Supplier, AI-provider and data-flow reviews
05
Recovery, access and change-control records
06
Reports, remediation guidance and retest outcomes
Cloud Security Alliance AI Trustworthy Pledge 2026Kotav Labs internal ISO/IEC 27001:2022 ISMS programme statusKotav Labs internal NIS2 implementation statusKotav Labs internal QNRCS self-assessment statusKotav Labs internal CIS Controls 8.1 self-assessment statusKotav Labs internal NIST CSF and AI RMF framework statusKotav Labs internal OWASP ASVS and SAMM methodology status
Green Web Foundation verified green hosting for kotavlabs.com
Plano de Recuperação e Resiliência, República Portuguesa e Financiado pela União Europeia — NextGenerationEU