Company/Trust & Compliance
Built to Meet Your Supervision Needs
Kliva is ISO 27001 certified. Our security work supports our clients' compliance with DORA, GDPR, and industry-specific supervisory requirements.
Compliance
Regulatory Compliance and Certifications
Kliva is ISO 27001 certified. Our framework is adapted to DORA, GDPR, and a documented Code of Conduct. Below is an overview of the standards and regulations we comply with.
ISO 27001
Kliva is ISO/IEC 27001 certified – a globally recognized standard for information security. This certification demonstrates a robust management system to protect data and systems, manage cybersecurity risks, and apply industry best practices. Our ISMS is audited annually by an accredited external auditor.
DORA
Kliva is adapted to the Digital Operational Resilience Act (EU 2022/2554), which imposes requirements for operational resilience across the supply chain for financial institutions. We provide a Register of Information, exit strategies, incident management procedures, and audit rights in accordance with DORA Articles 28-30.
GDPR
Kliva complies with GDPR and applicable sector-specific regulations. We implement strict controls to protect personal data, offer full transparency in data processing, and ensure data subject rights according to the data protection regulation.
Code of Conduct
Kliva has a documented Code of Conduct that sets clear ethical principles for all employees, board members, consultants, and partners. It covers integrity in business, workplace respect, data management, intellectual property rights, whistleblowing, and environmental responsibility.
Säkerhet
Infrastructure and Access Protection
Kliva operates on Nordic infrastructure with strong isolation, encryption, and access control. Enterprise customers can enable MFA and SSO/SAML to integrate Kliva with their own identity platform.
Infrastructure Security
Kliva hostas hos Elastx i fyra svenska tillgänglighetszoner med geografisk redundans. All kunddata lagras inom Sverige. Data krypteras i transit (TLS 1.2+) och i vila (AES-256). Nätverken är segmenterade med strikt brandväggspolicy, och produktionsmiljön är isolerad från utvecklings- och testmiljöer.
Multi-Factor Authentication (MFA)
Kliva supports MFA for all users via TOTP (Authenticator apps) and SMS. Administrators can require MFA for the entire organization or for specific roles. All internal Kliva systems require MFA for all personnel with access to the production environment or client data.
SSO and SAML 2.0
Enterprise clients can activate Single Sign-On via SAML 2.0 and integrate Kliva with their identity provider — Okta, Microsoft Entra ID (Azure AD), OneLogin, and other SAML-compatible platforms are supported. SCIM-based user provisioning is available upon request.
Role and Access Control
Granular Role-Based Access Control (RBAC) at organization, portfolio, and object level. The principle of least privilege is consistently applied. A full audit log of access and changes is available to administrators and can be exported to your SIEM.
Subprocessors
Subcontractors
Kliva collaborates with several subcontractors to deliver the service.
Documentation
Documentation on request
The following documentation is available for customers and prospects. All documents are released under a signed NDA.
- Kliva DORA Compliance Statement (extended version)
- ISO 27001 Certificate and Statement of Applicability
- Register of Information (ICT providers)
- Incident classification matrix
- Summary of annual penetration test
- Kliva Code of Conduct (full version)
Senast uppdaterad: 28 augusti 2026.Version 1.0.For questions:hello@kliva.com
