Compliance posture
Kernel maintains an information security program that substantially conforms to the ISO/IEC 27002 control framework, with active certifications across SOC 2 Type II, HIPAA, ISO 27001, and GDPR. The security practices page covers product security, infrastructure security, organizational security, and incident response in full, and the shared responsibility model covers the split between what Kernel secures and what you do. Reports and security artifacts are available through the trust center.HIPAA
Kernel signs a BAA on the Enterprise plan. Each browser runs in its own microVM with its own kernel and filesystem, which is the isolation boundary the BAA rests on. Pair it with zero data retention if PHI must not persist after a session ends.Zero data retention
ZDR is Enterprise-only and configured per organization. With it enabled, Kernel suppresses persistence of session recordings, live view streams, and telemetry, so session data isn’t retained after the browser terminates. It’s scoped per surface — tell us which ones you need suppressed.What else the Enterprise plan includes
Full plan comparison is on pricing and limits.