Kushki Logo

Security Trust Center

Start your security review
View & download sensitive information
ControlK

Overview

At Kushki, we move money securely for businesses across Ecuador, Colombia, Peru, Chile, and Mexico, which means security isn't a separate department, it's the product.

We protect every transaction with three layers of defense: PCI DSS Level 1 compliance for card data handling, tokenization that turns your customers' real card numbers into data that's useless to any attacker, and a certified encrypted vault for everything else. On top of that, over 200 machine learning-based fraud rules and configurable 3DS monitor every charge in real time.

Want proof? Active certifications you can review right here: ISO/IEC 27001, PCI DSS, PCI PIN, and SOC 2 Type 1. We don't ask you to take our word for it — we give you access to the documentation.

Our ISMS is aligned with ISO 27001 and is mandatory across every subsidiary in the group, without exception. Read our full commitment in our Information Security Policy.

Want to stay up to date? Check out our Security Tips and Security Bulletins, maintained by our own Information Security team.

Need an audit report or a restricted document? Request it right here — we respond quickly.

  • SecurityScorecard
  • Amazon Web Services
  • Nordstern Technologies • NCS
  • A-LIGN
  • GM Sectec
  • ICONTEC

Documents

COMPLIANCEISO/IEC 27001

Policies

We are currently working with experts to put together our company policies. Please contact us for more details.

Risk Profile

We have secure, reliable hosting that customers can depend on. We are happy to provide details about our risk mitigation practices and recovery objectives upon request.

Incident Response

We have a dedicated team that responds to security incidents. We are happy to provide more details about our incident response practices upon request.

Data Privacy

Privacy of customer data is top of mind. We follow industry best practices and follow all applicable privacy regulations.

Product Security

We pay great attention to enterprise features such as access control and single sign on. We are happy to provide more details about our enterprise features upon request.

Reports

We may provide security-related reports upon request.

Data Security

We follow industry best practices for data security. We are happy to provide more details about our data security practices upon request.

Access Control

Access is tightly monitored and controlled at our company. We are happy to provide more details about our access control practices upon request.

App Security

We take application security seriously and are putting together a program to monitor internal apps.

Infrastructure

We take great care to work with best-in-class infrastructure providers that provide secure computing and storage. We are happy to provide more details about our infrastructure upon request.

ESG

We prioritize and take environmental, social, and governance (ESG) considerations seriously in our operations and decision-making processes.

Legal

We take legal matters seriously and we always engage our legal counsel to review all commercial activities. Please contact us if you have any questions.

Endpoint Security

We follow industry best practices for endpoint security. We are happy to provide more details about our endpoint security practices upon request.

Network Security

We protect our corporate network against external & internal threats.

Corporate Security

We implement internal measures and practices to maintain a high standard of security.

Risk Management

We have a dedicated team that manages security risks. We are happy to provide more details about our risk management practices upon request.

Asset Management

We have strict asset management policies in place to ensure that all assets are accounted for and secure.

BC/DR

We have a business continuity plan in place to ensure that we can continue to operate in the event of a disaster.

Training

We provide security awareness training to all employees to ensure that they are aware of security best practices.

Change Management

We have a change and configuration management process in place to ensure that changes are properly reviewed and approved.

Physical & Environment

We have physical and environmental controls in place to ensure that our headquarters and facilities are secure and reliable.

Continuous Monitoring

We continuously monitor our systems for security threats and vulnerabilities. We are happy to provide more details about our continuous monitoring practices upon request.

If you think you may have discovered a vulnerability, please send us a note.
Report issue
Built onSafeBase by Drata Logo