İçeriğe geç
All systems operational — 99.997% uptime
Platform · Security 14

Security, by default.

SOC 2 Type II, ISO 27001, PCI-DSS L1, KVKK compliance. Card data never touches Karum, customer data stays in Turkey, every admin action goes to an append-only log.

SOC 2
Type II
Annual audit
ISO 27001
InfoSec
Certified
PCI-DSS
L1
Payment security
KVKK
+ GDPR
Data in Turkey
What it does

Certified, audited, transparent security.

4 certifications

SOC 2 Type II, ISO 27001, PCI-DSS L1, KVKK — annual independent audits.

KVKK + data residency

Customer data stored in Turkey; even backups don't leave the country.

PCI-DSS L1 vault

Card data never touches Karum; tokenized at the provider.

Append-only audit log

Every admin action, login, role change, refund — recorded immutably.

How it works in Karum

How data access is governed.

Step 01

SSO + 2FA

Office 365 / Google Workspace SSO + 2FA (TOTP / WebAuthn).

Step 02

Role-based permissions

Fine-grained ability via CASL: subject + action + condition + tenant scope.

Step 03

Audit

Every read/write + IP + user-agent recorded append-only.

Step 04

Encryption

Disk-at-rest AES-256, transit TLS 1.3, sensitive fields encrypted at the application level.

Step 05

Pen-test

Two independent pen-tests per year; 24/7 bug bounty program.

Step 06

Incident response

PSIRT 24/7; KVKK requires breach notification within 72 hours.

Feature details

In security, the details we care about.

01
Turkey data residency

Customer and order data only in Turkish regions; backups don't leave the country.

02
PCI-DSS L1

Card data tokenized; Karum service never sees card numbers.

03
SSO + 2FA

Office 365, Google Workspace, Okta, Azure AD; 2FA TOTP/WebAuthn.

04
Role-based permissions

CASL ability check + tenant scope guard on every endpoint.

05
Append-only log

UPDATE+DELETE revoked at the DB role level; audit-ready.

06
Encryption

AES-256 at-rest, TLS 1.3 transit, application-level envelope for sensitive fields.

07
Incident response

PSIRT 24/7; KVKK 72-hour notification; bug bounty program open.

Customer voice
We went through a KVKK audit. Karum documented that our data is in Turkey, the auditors reviewed the audit log and approved. Zero open questions.
YO
Yiğit Oraman
DPO, Telnet Bilişim
Plan coverage

Available on

Starter Growth Pro Enterprise (SSO/SAML)
See all plan details
Getting started

Your first sale this week. Setup in 5 minutes.

Our onboarding team runs the process. Data migration, product mapping, and channel connection included — first sale on average in 3–7 days.

LET'SGO