Karsaaz Solutions logo
Karsaaz Solutions

Compliance, built into every platform

Every product we ship is engineered in alignment with PCI DSS, ISO 27001, SBP, and AML/CTF frameworks. Our compliance posture is documented, reviewed, and audit-ready.

NDA + DPA · 24h
CAIQ · on request
SIG-Lite · on request
Compliance Platform
Background
Stats background

Standards

4 tracked

Target SLA

99.9%

Encryption

AES-256

Audit cadence

Annual

One Baseline. Every Platform

Karsaaz operates a single, documented control plane — the same security and compliance standards apply across every product, every deployment, and every customer engagement.

Encryption

AES-256

at-rest · TLS 1.3 in transit

Architecture

Multi-AZ

high-availability ready

Target MTTR (P1)

< 1 hour

response framework live

Data residency

PK default

region-locked option

Six Standards One Framework

Our compliance roadmap covers the standards our partners and clients rely on.

Image
Image
Image
Image
Image
Image
Image
Image
Image
Image
Image

PCI-DSS Level 1

QSA-led audit in progress. Target: Q3 2026 · annual cycle.

In Progress
Image
Image

27001

ISO/IEC 27001

Gap analysis complete · ISMS implementation underway. Target: Q4 2026 · 3yr cycle.

In Progress
Image
Image
Image
Image

Type II

SOC 2

SOC 2 Type II

Readiness planning underway. Target: Q1 2027 · annual cycle.

In Progress
Image
Image
Image
Image

SBP

SBP-aligned

Controls aligned with BPRD, PRISM, and EIFD frameworks. Reviewed annually.

Available
Image
Image

AML / CTF

Sanctions, PEP screening, and transaction monitoring built in. FATF-aligned.

Available
Image
Image
Image

CAIQ · SIG-Lite

Vendor assessment packs available under NDA. On request.

Available

Defense in depth,
by design

WAF
WAF
DDoS protection
DDoS protection
mTLS termination
mTLS termination
Geo-fence options
Geo-fence options

Six steps Always on

1

Continuous

Controls drift tracked through internal monitoring.

2

Quarterly

Internal review and evidence consolidation.

3

Pre-audit

Auditor walkthrough and gap closure.

4

Audit window

2–6 weeks · evidence retrieval and Q&A.

5

Attestation

Report issued and shared with clients under NDA.

6

Re-attest

Annual cycle · continuous improvement goal.

Governance Matrix

CONTROL DOMAINSTANDARDVERIFICATION DETAILCADENCESTATUS
Data residencySBP / GDPRGeofencing & Storage LocalizationContinuousACTIVE
EncryptionFIPS 140-2AES-256 Key Rotation VerificationDailyACTIVE
Access controlISO 27001User access reviews & mFA logsMonthlyACTIVE
Audit loggingPCI DSSImmutability checks & RetentionContinuousACTIVE
Vulnerability mgmtSOC 2Scanning & Remediation TimelinesWeeklyACTIVE
BCP / DRISO 27001Failover testing & RPO/RTO validationAnnualACTIVE
Vendor riskSIG-LiteThird-party assessment reportsAnnualACTIVE
Incident responseAML / CTFRunbook testing & Disclosure logsQuarterlyACTIVE

Eight controls, one stack.

Tokenisation

Sensitive data replaced with non-reversible tokens.

Key management

Hardware-backed lifecycle management for secrets.

Network isolation

Complete environment segregation by default.

Secret rotation

Automated credential updates without downtime.

Tamper-evident logs

Cryptographically signed audit trails for integrity.

Anomaly detection

AI-driven behavior analysis across infra logs.

Access reviews

Just-in-time access with mandatory peer reviews.

Drift detection

Automated infra remediation for baseline drift.

Your Questions, Answered
Which standards are tracked?

PCI-DSS L1, ISO 27001, SOC 2 Type II, SBP-aligned, AML/CTF-aligned. Active audits and targets are published in our compliance roadmap.

Can we get the compliance pack under NDA?

Yes — NDA + DPA executed within 24 hours. Pack includes CAIQ, SIG-Lite responses, architecture overview, and current attestation status.

How is customer data isolated?

Per-tenant keys, residency-locked deployments, and RBAC enforced at application and data layers.

What is your incident disclosure cadence?

P1 incidents are disclosed within 24 hours via the status page. Detailed post-mortems are shared with affected clients within 5 business days.

Do you support GDPR + SCCs?

EU-corridor support is available on request. A DPA with Standard Contractual Clauses is provided on engagement.

Who owns the audit evidence?

The customer. Evidence packs are exported at each milestone for client retention.