
Trust and security at Kaam for Enterprise.
Every record is a person.
The systems we build hold people's names, phone numbers, documents, test results and sometimes their health. We treat each record as the person it describes: kept in India, seen only by the people whose work needs it, logged whenever anyone opens it, and deleted when its purpose ends.
Kaam Job Career Pvt Ltd is ISO/IEC 27001:2022 certified. Certificate No. 26MEQXM37, issued by Magnitude Management Services Pvt Ltd (EGAC accredited), valid to 18 September 2029.
The certification covers the company's information security management system. A product or a client's deployment is not certified in its own right; each runs under the company's controls and the terms of your contract. The full statement is at kaam.com/security.
In India. Client data, backups and logs are kept in Indian data centres.
- Access by role, with the least access each job needs.
- A person's record is visible only to the people whose work needs it. Above them, aggregates.
- Every view of a personal record is logged, and your admins can read the log.
- Consent is recorded for every person, in their language, with the purpose stated, and it can be withdrawn.
- For anyone under 18, a parent's consent by OTP comes first.
- Our systems are built for the Digital Personal Data Protection Act, 2023 and its rules.
Health and wellbeing data is kept apart, seen by the fewest people, and used only for care. Children's data is never used for advertising or profiling.
- Your data never trains a model.
- The AI providers we use for your data keep nothing.
- Every AI feature ships with a written safety rule, in the code.
- Anything that changes a person's life (a hiring decision, a government fact, a crisis flag) goes to a person.
- Pay is never invented.
Encryption in transit and at rest · single sign-on · two-factor sign-in for admins · code review on every change · a third-party security test before every go-live · daily backups with tested restores · recovery targets in your contract · a status page for every live system.
Your code, your data and your documents are yours. Whenever you ask, we move them to your cloud in open formats.
Use the form and choose Report a security issue, or see kaam.cc/.well-known/security.txt. We acknowledge every report within one working day.
The security and procurement pack: company facts, the certificate, policy summaries, a data processing agreement, our list of sub-processors and our insurance.
Is Kaam ATS (or any product) ISO certified?
The certification belongs to the company, Kaam Job Career Pvt Ltd. Our products are built and run under its information security management system.
Where is our data stored?
In Indian data centres, with backups and logs in India.
Will you sign our data processing agreement?
Yes, or we can start from ours.
Can we audit you?
Yes, with notice, against the controls in your contract.
How do you handle the DPDP Act?
Our systems are built for it: notice and consent in the person's language, purpose limits, withdrawal, deletion when the purpose ends, and parental consent for children.
Tell us what should change.
A programme, a platform, a process that lives on spreadsheets. We’ll reply with the outcome we’d agree to, a plan, or an honest no.
Request the security and procurement pack ↗