Security & compliance
Auditable by design.
Kivi runs financial data for tens of thousands of businesses and for banks that are also our shareholders. That means security is not a page on the website — it is a requirement our products are audited against.
Controls
What is in place
🔐Role-based access
Granular permissions per module, company and branch; least-privilege by default.
📋Transaction logs
Every create, change and approval is recorded with user, time and source; logs are exportable.
⚙️Secure APIs
Token-based authentication, scoped credentials, rate limiting and signed webhooks.
🛡️Data protection
KVKK and GDPR-aligned processing, encryption in transit and at rest, documented retention periods.
🧾E-document compliance
Statutory e-invoice, e-archive, e-dispatch flows with validated formats and archiving.
✦AI-assisted risk analysis
AML screening, PEP and sanction lists, and anomaly detection on transactions. ✦
Governance
Bank-grade oversight
Products developed with partner banks are reviewed under their own audit and information-security processes. Corporate governance, investor reporting and incident procedures follow the same discipline.
Joint audits
Partner banks audit the platform and the development process, not just the output.
Environment separation
Development, test and production are isolated; production access is logged and time-limited.
Incident response
Defined severity levels, notification duties and post-incident reporting.
Documents
Legal texts
Privacy notices, cookie policy and processing notices are published in Turkish for statutory reasons. English summaries are available on request for enterprise due diligence.
Privacy & KVKK
Data processing notices per channel (customer, employee, candidate, call centre, CCTV).
Turkish page →
Turkish page →
Cookie preferences
Consent categories, retention and Google Consent Mode signals.
Open preferences →
Open preferences →
WhatsApp privacy
How WhatsApp Business messages are processed and retained.
Turkish page →
Turkish page →
Doing vendor due diligence?
We can share our security pack, architecture overview and reference audit summaries under NDA.