Security & compliance
Auditable by design.
Kivi runs financial data for tens of thousands of businesses and for banks that are also our shareholders. That means security is not a page on the website — it is a requirement our products are audited against.
Controls
What is in place
- 🔐Role-based access Granular permissions per module, company and branch; least-privilege by default.
- 📋Transaction logs Every create, change and approval is recorded with user, time and source; logs are exportable.
- ⚙️Secure APIs Token-based authentication, scoped credentials, rate limiting and signed webhooks.
- 🛡️Data protection KVKK and GDPR-aligned processing, encryption in transit and at rest, documented retention periods.
- 🧾E-document compliance Statutory e-invoice, e-archive, e-dispatch flows with validated formats and archiving.
- ✦AI-assisted risk analysis AML screening, PEP and sanction lists, and anomaly detection on transactions. ✦
Governance
Bank-grade oversight
Products developed with partner banks are reviewed under their own audit and information-security processes. Corporate governance, investor reporting and incident procedures follow the same discipline.
- Joint audits Partner banks audit the platform and the development process, not just the output.
- Environment separation Development, test and production are isolated; production access is logged and time-limited.
- Incident response Defined severity levels, notification duties and post-incident reporting.
Documents
Legal texts
Privacy notices, cookie policy and processing notices are published in Turkish for statutory reasons. English summaries are available on request for enterprise due diligence.
-
Privacy & KVKK
Data processing notices per channel (customer, employee, candidate, call centre, CCTV).
Turkish page → -
Cookie preferences
Consent categories, retention and Google Consent Mode signals.
Open preferences → -
WhatsApp privacy
How WhatsApp Business messages are processed and retained.
Turkish page →
Doing vendor due diligence?
We can share our security pack, architecture overview and reference audit summaries under NDA.