
Kombo
Security and trust center evidence
Unified API for HR, payroll and recruiting software
Summary
Kombo has 4 vendor-stated rows in the CertReports index, last verified 18 Sep 2026. The strongest row is HIPAA: Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured). This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.
Reviewer brief
Kombo states it holds that it will sign a business associate agreement. Kombo states it holds a SOC 2 Type II report. Kombo states it holds a data processing agreement. Kombo states it holds an ISO/IEC 27001 certificate.
- HIPAA: Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured) (as of 18 Sep 2026)
- SOC 2: Vendor states SOC 2 on its trust centre (as of 18 Sep 2026)
- GDPR: Vendor states GDPR on its trust centre (as of 18 Sep 2026)
Facts only, each dated; nothing here is inferred, scored or advised.
Evidence count
0verified rows
Compliance grid
- HIPAAVendor-stated
Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured)
as of 18 Sep 20261 source
SOC 2Vendor-statedVendor states SOC 2 on its trust centre
as of 18 Sep 20261 source- GDPRVendor-stated
Vendor states GDPR on its trust centre
as of 18 Sep 20261 source
ISO/IEC 27001Vendor-statedVendor states ISO/IEC 27001 on its trust centre
as of 18 Sep 20261 source
Legal artefacts
Subprocessors (2)
- DPData Processing Agreement Master Services
- ISInfrastructure Status Monitoring Google Cloud