Security & compliance

Auditable by design.

Kivi runs financial data for tens of thousands of businesses and for banks that are also our shareholders. That means security is not a page on the website — it is a requirement our products are audited against.

Request the security packEnterprise architecture
Controls

What is in place

  • 🔐Role-based access Granular permissions per module, company and branch; least-privilege by default.
  • 📋Transaction logs Every create, change and approval is recorded with user, time and source; logs are exportable.
  • ⚙️Secure APIs Token-based authentication, scoped credentials, rate limiting and signed webhooks.
  • 🛡️Data protection KVKK and GDPR-aligned processing, encryption in transit and at rest, documented retention periods.
  • 🧾E-document compliance Statutory e-invoice, e-archive, e-dispatch flows with validated formats and archiving.
  • AI-assisted risk analysis AML screening, PEP and sanction lists, and anomaly detection on transactions. ✦
Governance

Bank-grade oversight

Products developed with partner banks are reviewed under their own audit and information-security processes. Corporate governance, investor reporting and incident procedures follow the same discipline.

  • Joint audits Partner banks audit the platform and the development process, not just the output.
  • Environment separation Development, test and production are isolated; production access is logged and time-limited.
  • Incident response Defined severity levels, notification duties and post-incident reporting.
Documents

Legal texts

Privacy notices, cookie policy and processing notices are published in Turkish for statutory reasons. English summaries are available on request for enterprise due diligence.

  • Privacy & KVKK Data processing notices per channel (customer, employee, candidate, call centre, CCTV).
    Turkish page →
  • Cookie preferences Consent categories, retention and Google Consent Mode signals.
    Open preferences →
  • WhatsApp privacy How WhatsApp Business messages are processed and retained.
    Turkish page →

Doing vendor due diligence?

We can share our security pack, architecture overview and reference audit summaries under NDA.

Start Free Talk to Sales
I'm an SMB I need an enterprise solution ✦ Discover AI