Trust Center

Security & Compliance

Trust in Akka and our products is foundational to our success, and our security and trust practices embody this.

Below are the four major facets of trust, security and compliance that let you rely on Akka for your mission-critical applications.

Information Security and Compliance

Akka's commitment to security and compliance is paramount leading to attestation or certification of 50 compliance standards and a plan to implement additional controls continually to meet our customer's needs.

Akka has been deployed into 1000s of mission-critical environments. Neither Akka's software nor our hosted environments, such as services provided at Akka.io, have ever had a security breach. We understand that our customer's trust in our software and in us is critical, and we prioritize researching and supporting new InfoSec initiatives.

Standards

Resources

Policies

Subprocessors

Amazon

Cloudsmith

Docebo

Google

HubSpot

Microsoft

Salesforce

Zoho

Controls

Governance

Governance - Akka Federated Plane SLA

Service Credits

If Akka fails to meet the uptime commitment or the latency commitment as defined Akka will credit back to Customer a for the period affected.

The service-credit is a percentage of the applicable fees for the affected period (for annual subscriptions, the monthly allocation of Customer's Fees (annual total Software and Managed Services spend)) to be credited to Customer, if Akka approves the claim, as set forth in the table below.

{|p{0.3}|p{0.3}|}

Monthly Uptime Percentage & Service Credit Percentage
|99.8\% - < 99.00\%| & |15\%|
|< 99.00\%| & |30\%|


{|p{0.3}|p{0.3}|}

Latency Percentile & Service Credit Percentage
|80\% - 90\%| & |15\%|
|<80\%| & |30\%|


For example, if, in a 30-day calendar month, the afp was unavailable for 24 hours when Customer's total annual Fees are \$120,000, the Monthly Uptime Percentage would be 96.7\%, the Service Credit Percentage would be 30\%, and the Service Credit would be 30\% * \$120,000 / 12 = \$3,000.

Governance - Audits

SOC 2 Type 2 Observation Period and Bridge Letter Cadence

Akka shall commission a SOC 2 Type 2 report from an AICPA-approved auditor covering a 12-month observation period at least every twelve months, and shall issue a bridge letter --- reissued at least quarterly --- to cover the interval between the end of each observation period and the availability of the next SOC 2 Type 2 report, so that customers experience continuous coverage of Akka's controls. The audit scope shall cover the Akka SDK, the Akka Agentic Orchestrator, and the dedicated customer-tenant environments hosted on the Akka Agentic Orchestrator together with their supporting services.

Annual Internal Control Effectiveness Assessment and Monitoring

Akka uses a custom internal platform to document their internal controls and continuously monitor their effectiveness. An assessment over the effectiveness and efficiency of the internal controls, processes and policies is reviewed by management on at least an annual basis and identified deficiencies are remediated accordingly.

Vendor Risk Assessment and Performance Evaluation

A vendor management process has been implemented whereby management performs risk assessments of potential new essential vendors and evaluates the performance of essential vendors on an annual basis. Corrective actions are taken as required based on the results of the assessments.

Annual Penetration Testing and Remediation

A penetration test is performed on an annual basis to identify security exploits. Issues identified are classified according to risk, analyzed and remediated in a timely manner.

Service Provider Review

On an annual basis, management performs reviews of SOC (or other) reports from service providers/vendors to review the appropriateness of scope, impact of identified exceptions and applicable complementary user entity controls.

Governance - CCD Data Protection

Exclusion of Customer Production Data from AI Systems

Akka shall not permit any AI System --- whether deployed internally or by a third-party tool provider engaged in the delivery of products or services --- to process or otherwise be exposed to customer production data held in a dedicated customer environment, unless the customer has provided express written consent to such processing through an affirmative opt-in.

Governance - CCD Data Residency

Handling of SOCI Act Protected Information

Akka shall treat any information received from or about a customer that constitutes soci-protected-information as Confidential Information of that customer, and shall record, use, and disclose such information only for purposes expressly permitted by the soci. Akka shall maintain a SOCI handling brief for each soci-regulated customer, segregate soci-protected-information from general service-delivery workflows, exclude it from training data sets and analytics, and require CISO sign-off for any external disclosure.

Governance - Conduct and Ethics

Reporting Code of Conduct and Ethical Issues

Akka has established communication channels that allow employees to securely and anonymously report issues related to fraud, harassment and other issues impacting Akka's ethical and integrity requirements.

Employee Confidentiality Agreement Onboarding

The company requires employees to sign a confidentiality agreement during onboarding.

Governance - Data Retention and Disposal

Data Purge and Removal of Customer Information

The company purges or removes customer data containing confidential information from the application environment, in accordance with best practices, when customers leave the service.

Data Retention and Disposal Policy

Formal data retention and disposal policy and procedure are in place to guide the secure retention and disposal of information.

Secure Disposal and Recycling of Data Storage Equipment

All equipment with data storage capabilities is disposed of or recycled securely.

Governance - Encryption and Key Management

Workstation Encryption and Password Protection

All company workstations have disk encryption and system passwords enabled.

Network Diagram Maintenance and Review

A formal network diagram outlining boundary protection mechanisms (e.g. firewalls, IDS, etc.) is maintained for all network connections and reviewed annually by IT management.

Governance - Management

Board Independence and Oversight Responsibilities

The majority of the board of directors is comprised of non-executive directors independent from management.

The board meets on at least a quarterly basis for oversight on internal controls, operations and business objectives. In the event that the board of directors consists of the same number of executive directors and non-executive directors, for any situations where voting needs a tie break, one non-executive director will hold two votes.

Executive Management Reviews

Akka's executive team meets at least quarterly to discuss operations, issues relating to internal controls and delivery on key performance metrics.

Security Roles and Responsibilities Training

Information security roles and responsibilities of employees, contractors, and the Company are stated in the Company's security awareness training.

Governance - Necessary Resources

System Documentation and User Guides

Akka has developed documentation and user guides that describe relevant system components as well as the purpose and design of the system. These documents are made available to both internal and external users and updated as needed.

Governance - Sanctions

AML/CTF Act and Financial-Crime Facilitation Prohibition

Akka shall not, in connection with the supply of its products and services, deal with any person or asset where to do so would cause Akka or any customer to breach the Australian AML/CTF Act 2006 (Cth) or facilitate the commission of any money laundering, terrorism financing, or similar financial crime.

Customer Notification of Change in Sanctions Standing

Akka shall notify each affected customer within 48~hours of internal confirmation that any continuing sanctions warranty given by Akka under that customer s Contract has become false, with particulars, remediation steps, and impact on service delivery.

Access Control

Access Control - Identification and Authentication

Multi-Factor Authentication for Administrative Access

Multi-factor authentication (MFA) is enforced for user accounts with administrative access to Akka's production platform.

Access Control - Physical Access

Logical and Physical Isolation of Customer Data

Each customer's data is logically or physically isolated from customer belonging to other customers. This separation is maintained at all times, through all components.

Access Control - Policy and Governance

Encryption of Data in Transit

Encryption technologies are used to protect communication and transmission of data over public networks and between systems.

Access Control - Privileged Access

Privileged and Shared Account Access Restrictions

Access to shared administrator/master/root accounts on the infrastructure supporting the application is restricted to authorized personnel via a group-based access scheme.

Software Development

Software Development - Practices

Emergency Change Management and Approval

Emergency change requests are documented and subject to the standard change management process but at an accelerated timeline. Prior to initiating an emergency change, appropriate approval is obtained and documented.

Change Documentation and Approval

Changes to the application(s) and supporting infrastructure are documented, tested and approved by authorized personnel prior to implementation into the production environment in accordance with the change management process.

Segregation of Development and Testing Environments

Changes to application and system infrastructure are developed and tested in a separate development or test environment before implementation.

AI

AI - Safety, Boundaries and Misuse Prevention

AI System Configuration Against Training on Customer Data

Akka shall not use an AI System on data classified as Customer-Production or as Confidential (including recordings and transcripts of customer or internal meetings where customer matters are discussed) until: (a) the AI System has been confirmed to be configured to prevent that data from being used for training, fine-tuning, developing or improving the underlying model or algorithm, or for any purpose unrelated to Akka's performance for the customer; and (b) Akka has rebutted in writing any automatic opt-in present in the AI System's licensing, usage, click-wrap, or hyperlinked terms. AI features in customer production environments shall remain off by default; activation shall require the customer's affirmative configuration and shall not be enabled by Akka absent an express customer opt-in.

Incidents

Incidents - Handling

Data Breach Notifications

Notifications regarding confirmed data breaches are provided to affected data subjects, regulators, and other parties (as applicable) within an acceptable timeframe to meet the Company's confidentiality commitments.

Patch Management and Quarterly Compliance Verification

A patch management process exists to confirm that operating system level vulnerabilities are remediated in a timely manner. Production servers are verified for patch compliance on at least a quarterly basis.

Incidents - Notification

Critical Infrastructure Customer Incident Notification

Akka shall maintain, for each customer subject to a statutory critical-infrastructure or operational-resilience incident notification regime, a hard internal service level of six hours between internal confirmation of a Notifiable Incident affecting that customer and the issuance of customer notification, in order to provide the customer with sufficient lead time to meet its own statutory notification window. Akka shall flag each such customer in its service-delivery records, embed the six-hour clock into the security on-call playbook, and rehearse the notification pathway at least annually in a tabletop exercise.

Workstation Patch Management and Auto-Update Verification

A patch management process exists to confirm that operating system level vulnerabilities for workstations are remediated in a timely manner. In addition, workstations are checked quarterly to ensure that auto updates are enabled.

Incidents - Recovery

Annual Disaster Recovery Plan Testing and Review

Disaster recovery plans (including restoration of backups) have been developed and tested annually. Test results are reviewed and consequently contingency plans are updated.

Supply-Chain

Supply-Chain - Supplier Management

Customer-Requested Subcontractor Withdrawal

Akka shall, on receipt of a reasonable request from a customer to cease using a specific subcontractor in the delivery of services to that customer, promptly do so and, where applicable, propose a substitute subcontractor for the customer's consent within a reasonable time, executing the substitution without additional cost or operational impact to the customer. The right does not extend to off-the-shelf third-party technology providers for which Akka does not have the practical ability to negotiate per-tenant withdrawal. Akka may decline a request that is not made on reasonable grounds, providing the customer with a written explanation.

Third Parties

Third Parties - Agreements

Contractual Restrictions on Third-Party AI Tool Use of Customer Data

Akka shall not engage a third party as an AI System provider in the delivery of products or services to a customer unless that third party is bound, in a written agreement with Akka, to a contractual prohibition against using Customer-Production or Confidential data (including meeting recordings and transcripts where customer matters are discussed) for training, fine-tuning, developing or improving any model or algorithm, or for any purpose other than performing services for Akka in support of Akka's obligations to the customer.

Endpoint Management

Endpoint Management - Workstations

Workstation Security and Malware Protection

All company workstations must have IT-approved antivirus (AV), firewall and anti-malware/intrusion software installed and operational.

Please see the list of approved antivirus software on the InfoSec Resources page in the Internal Wiki. Agent software to verify other requirements may also be required.

Communications

Communications - Policy

Provides Separate Communication Lines

The company has security and privacy incident response policies and procedures that are documented and communicated to authorized users.

Product and Service Descriptions for Users

The company provides a description of its products and services to internal and external users.

Customer Contract Review and Approval for Security and Confidentiality Commitments

Customer contracts are reviewed and approved to ensure that security and confidentiality commitment are met.

External Support System and Incident Reporting

Akka provides an external-facing support system that allows users to report suspected defects, complaints, issues, and any other challenge through an appropriate channel. Reported tickets are addressed by Akka's support staff in a timely manner.

Infrastructure

Infrastructure - Configuration Management

Production Server Antivirus Protection

Antivirus software is in place on the production servers to prevent or detect and act upon the introduction of unauthorized or malicious software.

Baseline Configuration Retention and Rollback Capability

Baseline configurations are retained within the configuration management tool for rollback capability anytime an approved configuration change is made.

Log Management and Access Restriction

A log management process has been formalized to make sure that access to change the log configuration and access to modify logs is restricted.

Infrastructure - Network

Prohibition of Production Data in Non-Production Environments

Policy guidelines prohibit the use of production data in testing or development environments.

Infrastructure - Policy

Formal Change Management Process and Annual Review

A formal change management process exists that governs changes to the applications and supporting infrastructure. The process document is reviewed by IT management on an annual basis and updated as needed.

HR

HR - Labor & Human Rights

Customer Notification of Modern Slavery, Forced Labour, or Human Trafficking Findings

Akka shall, on identification of any instance of modern slavery, forced labour, or human trafficking within its business operations or supply chain that affects service delivery to a customer, promptly notify each affected customer with the particulars of the instance, the steps Akka is taking to investigate and address it, and the proposed timeframe for resolution.

HR - Performance Reviews

Information Security Awareness Training Participation

Employees are required to complete an information security and awareness training within 30 days of the the time of onboarding and annually thereafter.

HR - Roles and Responsibilities

Organizational Chart and Reporting Lines

Akka has established an organization chart that defines organizational roles, reporting lines, and authorities as it relates to development, quality assurance, and security operations of its services. Akka's organizational structure is reviewed and updated in case of significant changes.

HR - Screening

Background and Reference Checks

Akka performs background checks on all new employees, and on any consultants who will have access to sensitive information.

Logging and Monitoring

Logging and Monitoring - Policy

System Activity Logging and Incident Alerting

Logging is enabled to monitor activities such as administrative activities, logon attempts, changes to functions, security configurations, permissions, and roles. Automated alerts are configured to notify IT management.

Artificial Intelligence

At Akka, we believe that the next wave of innovation in agentic AI will only be possible if it is built on a foundation of trust.

Trustworthy AI is not a feature you can simply add at the end; it must be an inherent part of the framework's design. Akka is engineered from the ground up to provide the bedrock of trust, but it is a shared responsibility. While our platform offers the essential tools and architectural principles, organizations using Akka must actively configure and implement the controls necessary to build trustworthy AI applications.

Read More

Resources

Application Security

Akka provides extensive facilities to allow you to construct trustworthy, secure and compliant applications.

Our documentation has even more details, linked below.

Resources

Akka Advanced Operations

A BYOC deployment of Akka Automated Operations is a specific isolated environment running in your cloud service of choice, fully in your control and with full transparency. Our team manages this environment to ensure you have the foundation for your critical applications, supported by our resilence and uptime guarantees.

Resources