Knowledge Catalyst
    Security & Compliance

    Audit-ready. By default.

    Four ISO certifications. Indonesia and Singapore data residency. Designed to meet the requirements of UU PDP, PDPA, GDPR, MAS, and Komdigi PSE to ensure full regulatory compliance.

    Certifications

    Audited to the standards regulators expect.

    ISO 27001:2022
    Information security

    ISMS controls audited annually.

    ISO 27701:2019
    Privacy information

    PIMS extension over 27001.

    ISO 27017:2015
    Cloud security

    Cloud-specific controls and shared-responsibility.

    ISO 27018:2025
    Cloud PII

    PII protection in public-cloud processing.

    Regulatory mapping

    Built for regulatory and audit compliance.

    OJK
    Indonesia banking — directory and competency rules
    UU PDP
    Indonesia personal data protection law
    PDPA
    Singapore personal data protection act
    Komdigi PSE
    Indonesia electronic system registration
    MAS
    Singapore monetary authority — fraud guidelines
    GDPR
    EU data protection
    Architecture

    The record itself is the proof: verified via digital signatures and ledger anchors.

    Credentials are cryptographically secured at issuance. Verification checks the verifiable digital signature and the blockchain anchor. Data sharing is privacy-preserved, and selective disclosure is fully controlled by the user

    Data residency

    Indonesia and Singapore. Region-pinned by jurisdiction. Designed for PDP / PDPA data-residency requirements.

    Encryption

    Encryption in transit (TLS 1.2+) and at rest. Hardware-backed key management.

    Audit trails

    Tamper-proof and anchored to the ledger, giving you a transparent, fully verifiable history for every record.

    Ecosystem security

    Infrastructure designed to meet strict internal and external governance standards.

    Get started

    Start verifying credentials today — free.

    Start free with a KC Passport, or request the full security pack for your procurement team.

    For procurement and risk teams

    Request our security pack.

    A 30-minute briefing with our enterprise team. Mapped to your regulator, your stack, your timeline.