Transport & browser hardening
Every page is served over HTTPS with HSTS, a content security policy, referrer and permissions policies, MIME-sniffing protection and framing restrictions.
ISO 27001 A.8.20-A.8.24 / SOC 2 CC6.6
Security & Compliance
This site applies the technical safeguards expected under GDPR, the SOC 2 Trust Services Criteria and ISO/IEC 27001 Annex A. Below is exactly what is in place and what an organisation-wide certification still requires.
Controls in place
Every page is served over HTTPS with HSTS, a content security policy, referrer and permissions policies, MIME-sniffing protection and framing restrictions.
ISO 27001 A.8.20-A.8.24 / SOC 2 CC6.6
All submissions carry cross-site request forgery protection, are schema-validated on the server, rate limited per sender, and screened by honeypot, timing and link heuristics.
ISO 27001 A.8.26 / SOC 2 CC6.1, CC7.2
We request only the fields needed to quote material or assess an application. Operational logs hold no message content and pseudonymise the sender's address.
GDPR Art. 5(1)(c), Art. 25
Measurement runs only after explicit opt-in, which can be withdrawn at any time. Access, correction, deletion and portability requests are answered within 30 days.
GDPR Art. 6, 7, 12-22
Hosting and email delivery run on managed providers that process data solely on our instructions, with transfers covered by standard contractual clauses.
ISO 27001 A.5.19-A.5.22 / SOC 2 CC9.2
Submission outcomes and application errors are logged for review, and a reported vulnerability or suspected breach is triaged on receipt with notification within 72 hours where required.
GDPR Art. 33 / SOC 2 CC7.3-CC7.4
Scope statement
SOC 2 and ISO/IEC 27001 certify an organisation, not a web page: both require an audited management system covering people, suppliers, devices and internal systems, assessed by an independent third party. This website is engineered to satisfy the technical criteria those frameworks test for, and to meet GDPR obligations for the personal data it collects.
We do not claim a current SOC 2 report or ISO/IEC 27001 certificate. Customers requiring one can request our current control documentation at sales@kmetal.us.
Remaining steps to certification
Appoint an owner
Name the person accountable for information security and privacy requests, and publish that contact.
Record of processing
Maintain the GDPR Article 30 record and a data processing agreement with each vendor.
Policies and training
Adopt written access control, acceptable use, incident response and retention policies, and train staff annually.
Independent audit
Engage an auditor for a SOC 2 Type II examination or an accredited ISO/IEC 27001 certification body.
Report a vulnerability
If you believe you have found a security issue on kmetal.us, email sales@kmetal.us with the steps to reproduce it. Please do not run automated scans, access other people's data, or publish the issue before we have had a reasonable opportunity to fix it. We acknowledge reports within five business days and will not pursue action against good-faith research that follows these terms.
Let’s talk material.