Skip to main content
What changes on the Enterprise plan, and where the artifacts live.

Compliance posture

Kernel maintains an information security program that substantially conforms to the ISO/IEC 27002 control framework, with active certifications across SOC 2 Type II, HIPAA, ISO 27001, and GDPR. The security practices page covers product security, infrastructure security, organizational security, and incident response in full, and the shared responsibility model covers the split between what Kernel secures and what you do. Reports and security artifacts are available through the trust center.

HIPAA

Kernel signs a BAA on the Enterprise plan. Each browser runs in its own microVM with its own kernel and filesystem, which is the isolation boundary the BAA rests on. Pair it with zero data retention if PHI must not persist after a session ends.

Zero data retention

ZDR is Enterprise-only and configured per organization. With it enabled, Kernel suppresses persistence of session recordings, live view streams, and telemetry, so session data isn’t retained after the browser terminates. It’s scoped per surface — tell us which ones you need suppressed.

What else the Enterprise plan includes

Full plan comparison is on pricing and limits.

Talk to us

Scoping an enterprise deployment, a BAA, or ZDR starts with a conversation: contact sales.