Many vendors talk about “security by design.” But each time you move your sensitive files to another vendor, you’re taking chances… Because it is not IF it happens, it is WHEN.
When you use Kanbanchi, your files stay on YOUR Drive. Authentication is managed by Google or Microsoft, and we do not store your passwords. Boards are encrypted by default and sit in Google Cloud.
If security matters to you, Kanbanchi is your best option.
Want detailed security and compliance information?
Access our Trust Center for security reports, compliance documentation, policies, and vendor risk information.
Kanbanchi maintains security, privacy, and compliance practices designed to help organizations protect their data and evaluate Kanbanchi as a trusted collaboration platform.

Kanbanchi is certified to ISO/IEC 27001:2022 by an independent certification body, confirming that Kanbanchi’s Information Security Management System (ISMS) is established, maintained, and continually improved in accordance with internationally recognized standards.
View a copy of the latest certificate in our Trust Center.

Kanbanchi’s SOC 2 Type II report, verified by an independent audit, reflects Kanbanchi’s commitment to maintaining strong security controls and protecting customer data.
View a copy of the latest report in our Trust Center.
Kanbanchi is CASA Tier II certified and adheres to CASA security standards to provide a high level of trust and protection for customers. Built on the globally recognized OWASP ASVS framework, CASA provides independent assurance that Kanbanchi meets strict application security requirements for cloud applications that access Google user data.
Kanbanchi is listed in the Cloud Security Alliance STAR Registry at Level 1. This provides additional transparency into Kanbanchi’s cloud security practices through a completed self-assessment.
Vendor security questionnaires and self-assessments, including CSA CAIQ, CAIQ Lite, HECVAT, HECVAT Lite, VSA Core, VSA Full, and VSAQ, are available in the Trust Center to support customer due diligence and vendor risk reviews.
Kanbanchi takes privacy obligations and the protection of customer information seriously. Kanbanchi maintains privacy and data protection practices designed to help protect personal data and support customers with applicable privacy and regulatory obligations.
Additional privacy frameworks supported by Kanbanchi, including regional data protection regulations, are documented in the Trust Center.
Compliance with privacy laws is a shared responsibility. Customers are responsible for configuring the platform appropriately, managing user access, and ensuring their use of Kanbanchi aligns with their own legal and regulatory requirements.
Learn more in the Kanbanchi Privacy Policy.

Kanbanchi supports customers subject to the General Data Protection Regulation (GDPR) by implementing privacy and security measures designed to help protect personal data, including appropriate technical and organizational safeguards. Learn more about Kanbanchi’s GDPR-related practices, data processing terms, and subprocessors in our Privacy Policy and Terms & Conditions.
Customers remain responsible for configuring the platform, managing user access, and ensuring their use of Kanbanchi aligns with applicable GDPR obligations.

Kanbanchi supports customers with UK data protection requirements, including UK GDPR and the Data Protection Act 2018. Kanbanchi applies privacy and security safeguards such as encryption, secure authentication, access controls, and subprocessor management to help protect personal data.
Customers remain responsible for configuring the platform and ensuring their use of Kanbanchi aligns with applicable UK data protection obligations.

Kanbanchi supports customers with international data transfer requirements under GDPR and UK GDPR. Where applicable, Kanbanchi relies on appropriate safeguards, including data processing agreements with subprocessors and transfer mechanisms such as the EU-US Data Privacy Framework and the UK Extension to the EU-US Data Privacy Framework as implemented by certified subprocessors.

Kanbanchi supports privacy practices aligned with the California Consumer Privacy Act, as amended by the California Privacy Rights Act, including transparency, data protection safeguards, and support for applicable privacy rights.
When processing personal information on behalf of customers under a service or subscription agreement, Kanbanchi acts as a service provider or processor. It processes such data solely in accordance with contractual terms and documented instructions, and does not sell personal information.
Customers remain responsible for determining whether CCPA/CPRA applies to their organization and ensuring their use of Kanbanchi aligns with applicable California privacy obligations.
Kanbanchi also cooperates with customers to help them fulfill their legal obligations, including responding to customer requests for access to or deletion of personal information.

Kanbanchi maintains privacy and data protection practices designed to help protect personal data, including technical and organizational safeguards, subprocessor management, and support for applicable data subject rights. These practices may support customers with obligations under Brazil’s Lei Geral de Proteção de Dados (LGPD), where applicable.
Kanbanchi maintains privacy and data protection practices designed to help protect personal information, including technical and organizational safeguards, subprocessor management, and support for applicable individual privacy rights. These practices may support customers with obligations under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), where applicable.

Kanbanchi supports education organizations with administrative and technical safeguards designed to help protect student education records. These include predefined user roles within the application, secure authentication, encryption in transit and at rest, internal access logging within Google Cloud Platform, and activity records that help track actions in the app.
FERPA compliance is a shared responsibility. Customers are responsible for configuring Kanbanchi appropriately, managing user access, and ensuring their use of the platform aligns with applicable FERPA requirements.

Kanbanchi is not directed to children under 13 and does not knowingly collect personal information from children as defined under COPPA. In educational settings, Kanbanchi may be used under the direction of schools or organizations, which are responsible for managing access and obtaining any required consents where applicable.

Kanbanchi has been trusted by healthcare organizations for over five years and can support security-conscious workflows when used with appropriate Google Workspace or Google Cloud configurations, applicable Business Associate Agreements, and customer-side safeguards.
Kanbanchi does not replace a covered entity’s or business associate’s HIPAA compliance program. Customers should confirm their agreements, access controls, retention settings, and data handling practices before using Kanbanchi with protected health information.
Learn more about Google Cloud HIPAA compliance.

Kanbanchi does not directly store payment card data in the application. Kanbanchi processes all payments through the payments provider, Braintree. Braintree is a validated Level 1 PCI DSS compliant service provider.
Customers and merchants remain responsible for understanding their own PCI DSS obligations, including the correct use of third-party payment processors and any applicable validation requirements.
Learn more about Braintree data security.
Looking for audit reports, security documentation, and compliance details?
Kanbanchi applies technical and organizational safeguards designed to help protect customer data and support secure collaboration. Kanbanchi’s data protection practices are designed to help keep customer data secure and managed within the controls of each organization.
Kanbanchi is hosted on Google Cloud Platform, supporting secure, reliable, and scalable service delivery. Kanbanchi conducts regular vulnerability scanning and periodic penetration testing to help identify and address security risks.
Kanbanchi uses Transport Layer Security to protect data transmitted between users and the application. Kanbanchi board data is encrypted at rest.
Kanbanchi uses Google Cloud Monitoring and Google Cloud Logging, which help identify issues quickly and support timely resolution.
Kanbanchi employees receive ongoing training in information security, data privacy, and password security. Confidentiality obligations are included in employee and contractor agreements.
Kanbanchi provides user management controls that help organizations manage access to the platform and keep collaboration secure.
Kanbanchi supports secure sign-in through Google Workspace and Microsoft 365. Authentication is handled by the customer’s identity provider, and Kanbanchi does not store user passwords.
Organizations can continue using their existing authentication policies, including multi-factor authentication and conditional access controls provided by Google or Microsoft.
Kanbanchi stores board data in Google Cloud with security protections designed to help safeguard customer information.
Files attached to Kanbanchi boards remain stored in Google Drive or Microsoft OneDrive within the customer’s environment, helping organizations maintain control over file storage, access permissions, and data management.
Kanbanchi provides predefined user roles and collaboration controls to help organizations manage access within the application. Attached files remain governed by Google Drive or Microsoft OneDrive permissions, helping teams collaborate using existing Google Workspace or Microsoft 365 security controls. In-app activity records help users and administrators understand actions taken within boards and workflows.
Have more specific questions about Kanbanchi security, compliance, data privacy, or access control? Contact us, and we'll be happy to help.