Trust Center I Kinaxis

Trusted by global supply chains

At Kinaxis, trust is foundational. We know our customers rely on us to protect their data, meet regulatory obligations, and operate their supply chains with integrity. This Trust Center brings together key information about our security, privacy, legal, and responsible technology practices.

Kinaxis Trust Center

Documentation requests

We’re happy to share documentation to support your due diligence and build trust in our program. Current customers can follow the links for each of the documents listed below. Prospective customers can request an NDA in order to access the documents.

Certifications and Memberships

Kinaxis maintains globally recognized certifications and attestations that demonstrate our commitment to keeping your data secure and our operations reliable. Reports and certificates relating to these items are available upon request and under NDA.

Kinaxis Maestro® undergoes independent third party SOC1 Type II and SOC2 Type II attestation audits.

Maestro has achieved C5 compliance, a cloud security-specific framework developed by the German Federal Office for Information Security (BSI) to meet the expectations of customers in Europe.

Kinaxis is certified under ISO 27001:2022, the international standard for information security management systems (ISMS), reflecting our commitment to maintaining strong, risk-based security controls across our operations.

Kinaxis is a Cloud Security Alliance Trusted Cloud Provider and maintains STAR Registry level 1. A Consensus Assessment Initiative Questionnaire (CAIQ) is publicly available.

Privacy

Managing personal data responsibly is essential to how Kinaxis delivers secure, compliant services to global customers. Our practices ensure we are meeting our legal requirements and reflect the trust our customers and employees place in us to handle personal data responsibly.

Quick Access

Subprocessors

We may engage trusted third party service providers (subprocessors) to support the delivery of our services. These providers are contractually required to meet our privacy and security standards.

Below is a current list of active subprocessors, including our own affiliates and third parties. View further instructions for current customers (such as our objection process and update notifications).

Kinaxis Affiliates

Entity Name Purpose / Service provided Country location Applied safeguard
Kinaxis Inc. Customer support, infrastructure maintenance and monitoring related to the Services Canada Adequacy decision
Kinaxis Corp. Same purposes as listed above United States of America Standard Contractual Clauses
Kinaxis Mexico SA Same purposes as listed above Mexico Standard Contractual Clauses
Kinaxis Europe B.V. Same purposes as listed above The Netherlands N/A
Kinaxis Ireland Limited Same purposes as listed above Ireland N/A
Kinaxis France SARL Same purposes as listed above France N/A
Kinaxis Germany GmbH Same purposes as listed above Germany N/A
Kinaxis Romania SRL Same purposes as listed above Romania N/A
Kinaxis UK Limited Same purposes as listed above The United Kingdom Adequacy decision
Kinaxis India Private Limited Same purposes as listed above India Standard Contractual Clauses
Kinaxis Japan K.K. Same purposes as listed above Japan Adequacy decision
Kinaxis Asia Limited Same purposes as listed above Hong Kong Standard Contractual Clauses
Kinaxis Singapore Pte. Ltd. Same purposes as listed above Singapore Standard Contractual Clauses
Kinaxis Korea Ltd. Same purposes as listed above South Korea Adequacy decision

Third Party Subprocessors

Subprocessor Purpose / Service provided Country location Applied safeguard
Microsoft Azure Cloud hosting and applicable infrastructure services. EEA, US, Canada, Japan, Australia Certified under the EU-U.S. Data Privacy Framework (US), Standard Contractual Clauses (Australia), Adequacy Decision (Canada, Japan)
Google Cloud Platform Cloud hosting and applicable infrastructure services. EEA, US, Canada, Japan, Australia Certified under the EU-U.S. Data Privacy Framework (US), Standard Contractual Clauses (Australia), Adequacy Decision (Canada, Japan)
Equinix Data center hosting services (co-location model). EEA, US Certified under the EU-U.S. Data Privacy Framework (US)
Vantage Data center hosting services (co-location model). Canada Adequacy Decision
Intermax Data center hosting services (co-location model). The Netherlands N/A
Quorum Cyber (Formerly Difenda) Cyber-security operations center (SOC) services, including security event monitoring. Responsible for identifying potential threats or suspicious activity on the SaaS Services environments and notifying Kinaxis for further action. Canada Adequacy Decision
Akamai Technologies Content delivery network, which allows users to connect to the SaaS Services using the same URL, while establishing an optimal path for performance in their region based on their applicable data center. US Certified under the EU-U.S. Data Privacy Framework

Compliance with global privacy laws

We comply with privacy regulations including the General Data Protection Regulation(GDPR), Canada’s Personal Information Protection and Electronic Documents Act(PIPEDA), and other applicable frameworks in the jurisdictions in which they apply. Our Privacy Policy outlines how we collect, use, store, and protect personal information, and explains the rights individuals have under applicable laws. Kinaxis applies data minimization principles across our systems and processes—we collect only the personal data necessary to support our services and limit access based on role and need. Oversight is provided by our Chief Legal Officer, who also serves as our Data Protection Officer, ensuring our privacy practices remain aligned with legal requirements.

Complying with the GDPR within Maestro

Maestro can support customers in meeting their obligations under the GDPR. The platform includes tools to help organizations respond to individual rights requests, including the right to access, correct, delete, or export personal data. Administrators can extract personal data in commonly used formats, make updates directly within the system, and configure user notifications to support transparency.

Requests to restrict or object to processing can be addressed by modifying or excluding relevant data from processing workflows. Personal data is retained only as long as necessary to support service delivery or legal obligations, and is securely deleted or de-identified when no longer required. Where personal data is transferred outside the EEA, Kinaxis relies on Standard Contractual Clauses (SCCs) and other approved mechanisms to ensure appropriate protection.

Maestro applies privacy and security by design, with technical safeguards such as encryption in transit, identity and access management, advanced threat detection, and disaster recovery planning. As the data controller, each customer is responsible for managing data subject requests within their Maestro environment. Kinaxis provides the tools and support to help meet those obligations.

Individual rights

Kinaxis users may have rights to access, correct, delete, or object to the processing of their personal data. These rights can be exercised by contacting us directly at dpo@kinaxis.com.

Data processing agreement

Our Data Processing Agreement (DPA) outlines the data privacy and protection practices Kinaxis and its affiliated entities follow when processing personal information on behalf of our customers in the provision of our products and services. It covers topics such as data processing roles, security measures, subprocessors, cross-border transfers, and compliance with global privacy laws. The DPA is available as part of our standard contracting materials to support customers in meeting their own legal and regulatory obligations.

Data hosting locations

Kinaxis hosts customer data in secure data centers located in North America, Europe, and Asia. Our hosting infrastructure includes both private and public cloud environments, with regional availability supported through providers such as Equinix, Google Cloud Platform, and Microsoft Azure.

Cross-border data transfers

Customer data may be processed or stored outside its country of origin. Where required, Kinaxis relies on Standard Contractual Clauses (SCCs) and other legally recognized safeguards to ensure appropriate protection of personal data transferred across borders.

Data retention and deletion

We retain personal data only as long as needed to meet our contractual, legal, or operational requirements. When no longer required, data is securely deleted or de-identified in accordance with our retention policy.

Cookies and tracking technologies

Kinaxis uses cookies and similar technologies to operate and improve our website, personalize content, and analyze usage patterns. For more details or to manage your preferences, please refer to our Privacy Policy.

Questions or requests

If you have questions about our privacy practices please contact privacy@kinaxis.com. To exercise your rights, please contact our Data Protection Officer at dpo@kinaxis.com.

Security

At Kinaxis, we recognize that the security of your supply chain data is paramount. Our commitment extends beyond our platform; we implement comprehensive security measures to protect your information across all facets of our operations.

Key Highlights

Hosting

Maestro is a cloud-based SaaS offering delivered from both private and public cloud infrastructures across regions, including North America, Europe and Asia. Under the private cloud model, we co-locate our infrastructures in enterprise-grade third party data center facilities, primarily with Equinix, and currently have arrangements with Google Cloud Platform and Microsoft Azure for the public cloud model. Depending on the engagement model, our hosting providers may support physical infrastructure, system setup, and environment management.

Physical security

At Kinaxis offices, physical access is restricted to authorized individuals based on job responsibilities and operational needs. Access is granted following the principles of “least-privilege” and “need-to-know”, and in alignment with our internal digital security program (DSP).

When an employee leaves the company, whether through resignation or termination, physical access is promptly revoked. All physical access tools, such as key cards or badges, are deactivated or collected as part of our offboarding process.

At our data center facilities, the providers are responsible for maintaining strict physical security and environmental controls and have been audited and/or certified based on ISO 27001, SOC 1 & SOC 2 Type II. Data center facilities are monitored by video surveillance and staffed security teams 24/7/365, with access to individual cages controlled by multi-factor authentication methods such as proximity cards, PINs, and biometric scans.

Identity and access management

Kinaxis’ customer access module supports single-sign-on (SSO). In cases where SSO is not leveraged by the customer, access may be granted using valid combinations of user IDs and passwords, in line with the password policy in effect at the customer.

All user activity within the platform is logged and tied to individual user IDs to ensure traceability. Security logs are retained for a minimum of 12 months.

Privileged accounts are regularly reviewed, monitored, and deactivated if no longer required. Access for departing Kinaxis employees is removed from systems and applications within one business day.

Customer access to Kinaxis systems is secured through encrypted channels. Customers are responsible for managing and controlling access for their own users within Maestro.

Encryption and data protection

Kinaxis uses strong encryption to help protect customer data both in transit and at rest.

Data at rest – Customer data is encrypted at the storage layer using at least AES-256 and XTS encryption mode. Backups are also encrypted during the backup process.

Data in transit – Data sent and retrieved by customers over unsecured channels (the Internet) is protected using HTTPS in combination with Transport Layer Security (TLS 1.2+). This supports AES 256-bit encryption algorithms when used with compatible browsers and configurations. Bulk data transfers to Kinaxis environments are secured in the same way.

Endpoint protection – All Kinaxis devices used to access customer environments have encrypted hard drives.

Vulnerability management

Intrusion detection and prevention– Kinaxis uses inline intrusion detection and prevention systems (IDS/IPS) to monitor network traffic for suspicious patterns and known threat signatures. These systems scan all packets in real time and block or reject traffic that appears malicious. IDS/IPS signatures are updated regularly to help ensure protection against emerging threats, including zero-day exploits. Logs are continuously monitored, and appropriate actions are taken when suspicious activity is detected.

Virus protection– Kinaxis uses on-access antivirus/malware detection, centrally managed. Virus definition files are automatically distributed and enforced. Systems with outdated definitions or identified threats are flagged and addressed through regular log reviews and automated remediation processes.

Vulnerability program management– Kinaxis follows an enterprise-wide vulnerability and patch management policy to help protect the confidentiality, integrity, and availability of our services. We use a risk-based approach to assess and prioritize remediation of identified vulnerabilities. Regular vulnerability scans are performed across systems and hosted applications. Ad hoc scans are also conducted in response to newly identified or reported threats that may affect our systems.

Logging and monitoring

Kinaxis regularly reviews logs from key components that support the Maestro platform, including firewalls, FTP servers, gateway servers, load balancers, and domain controllers.

In addition, all network devices, server infrastructure, services, application performance counters, and most application processes are continuously monitored using dedicated monitoring tools. High-priority incidents trigger real-time alerts that are escalated to the appropriate teams, with coverage in place 24/7/365.

Secure development lifecycle

Kinaxis integrates security throughout our Agile-based software development lifecycle (SDLC), combining secure coding practices, threat modeling, and structured change management. We incorporate the Microsoft Security Development Lifecycle into our SDLC to help ensure security is considered from design through deployment. Kinaxis R&D teams regularly conduct peer code reviews and follow established change management processes for all system updates.

Third party security assessments (penetration testing)

Kinaxis conducts regular security assessments through a comprehensive testing program. Each service update (SU) is internally tested by the Kinaxis product security team and included in quarterly “red team” exercises. In addition, our products undergo annual security testing by an independent third party. Test reports are made available to customers through our online portal and to prospective customers under NDA.

Change management

Kinaxis follows a formal change management process to ensure changes are properly assessed, approved, and implemented with minimal risk to operations. All changes are documented in a change record and include an evaluation of risk, including potential security impacts. Proposed changes must be reviewed and approved before moving forward. Changes to infrastructure and software are developed and tested in a separate test environment before implementation. Relevant stakeholders are informed as part of the change process to support coordination and transparency.

Incident management

Kinaxis maintains a formal Security Incident Response Plan (SIRP) to guide the detection, escalation, and resolution of security incidents. Incidents may be reported from a variety of sources, including employees, contractors, customers, our Security Operations Center (SOC), business partners, and hosting providers. In addition, third party Security Information and Event Management (SIEM) tools are in place to enable continuous log review and real-time threat detection.

Business continuity and disaster recovery

Kinaxis uses a combination of backup and data replication technologies to support the recoverability of customer data and meet defined recovery objectives. The disaster recovery plan is reviewed and tested at least once per year. A summary of the test results is available to customers through the Kinaxis Knowledge Network.

Data retention and deletion

Kinaxis customers retain full ownership and control over their data. Unless otherwise requested, customer data remains in the Maestro environment for the duration of the subscription term. After the term ends, data is permanently deleted thirty days after expiration of the subscription term, using NIST-approved data deletion methods.

Employee security and privacy practices

All Kinaxis employees undergo pre-employment background checks and sign confidentiality agreements as a condition of hire. Security and privacy training is required during onboarding and reinforced through monthly learning activities. In addition, employees review and acknowledge key corporate governance, security and privacy policies on an annual basis.

Legal

At Kinaxis, our legal practices reflect a commitment to ethical business, innovation, and compliance. This section outlines how we structure our contracts and policies to support transparency and responsible operations globally.

Quick access