Security & Compliance

Security and Compliance at K Metal

This site applies the technical safeguards expected under GDPR, the SOC 2 Trust Services Criteria and ISO/IEC 27001 Annex A. Below is exactly what is in place and what an organisation-wide certification still requires.

Controls in place

Transport & browser hardening

Every page is served over HTTPS with HSTS, a content security policy, referrer and permissions policies, MIME-sniffing protection and framing restrictions.

ISO 27001 A.8.20-A.8.24 / SOC 2 CC6.6

Form and request protection

All submissions carry cross-site request forgery protection, are schema-validated on the server, rate limited per sender, and screened by honeypot, timing and link heuristics.

ISO 27001 A.8.26 / SOC 2 CC6.1, CC7.2

Data minimisation

We request only the fields needed to quote material or assess an application. Operational logs hold no message content and pseudonymise the sender's address.

GDPR Art. 5(1)(c), Art. 25

Consent and data subject rights

Measurement runs only after explicit opt-in, which can be withdrawn at any time. Access, correction, deletion and portability requests are answered within 30 days.

GDPR Art. 6, 7, 12-22

Vendor management

Hosting and email delivery run on managed providers that process data solely on our instructions, with transfers covered by standard contractual clauses.

ISO 27001 A.5.19-A.5.22 / SOC 2 CC9.2

Monitoring and incident response

Submission outcomes and application errors are logged for review, and a reported vulnerability or suspected breach is triaged on receipt with notification within 72 hours where required.

GDPR Art. 33 / SOC 2 CC7.3-CC7.4

Scope statement

What certification means.

SOC 2 and ISO/IEC 27001 certify an organisation, not a web page: both require an audited management system covering people, suppliers, devices and internal systems, assessed by an independent third party. This website is engineered to satisfy the technical criteria those frameworks test for, and to meet GDPR obligations for the personal data it collects.

We do not claim a current SOC 2 report or ISO/IEC 27001 certificate. Customers requiring one can request our current control documentation at sales@kmetal.us.

Remaining steps to certification

  1. 01

    Appoint an owner

    Name the person accountable for information security and privacy requests, and publish that contact.

  2. 02

    Record of processing

    Maintain the GDPR Article 30 record and a data processing agreement with each vendor.

  3. 03

    Policies and training

    Adopt written access control, acceptable use, incident response and retention policies, and train staff annually.

  4. 04

    Independent audit

    Engage an auditor for a SOC 2 Type II examination or an accredited ISO/IEC 27001 certification body.

Report a vulnerability

Responsible disclosure.

If you believe you have found a security issue on kmetal.us, email sales@kmetal.us with the steps to reproduce it. Please do not run automated scans, access other people's data, or publish the issue before we have had a reasonable opportunity to fix it. We acknowledge reports within five business days and will not pursue action against good-faith research that follows these terms.

Let’s talk material.

Your next requirement.
Our next conversation.

Start an inquiry
© 2026 K Metal.