Security and Compliance you can trust

Kahootz is a sovereign collaboration platform trusted by government and enterprise to store and share OFFICIAL and OFFICIAL-SENSITIVE information. Every control we operate is independently audited.

ISO 27001 certified · Cyber Essentials Plus · CHECK tested · Sovereign-hosted

Chosen to protect information across UK government and defence

Kahootz has been supplying secure cloud services to the UK Government since 2002, and we remain absolutely committed to keeping your data secure while providing a well-supported, highly available service. Our commitment guarantees a minimum uptime of 99.95%, UK-based monitoring and support, and a robust implementation of all 14 of the NCSC’s Cloud Security Principles.

99.95%

Minimum service availability, guaranteed in our SLA

24h

UK-based infrastructure monitoring and support

14/14

NCSC Cloud Security Principles evidenced

Verified by independent standards

A security claim is only as good as the evidence behind it. Kahootz is independently audited every year against the UK’s recognised security standards, including ISO 27001, CHECK and Cyber Essentials Plus.

ISO 27001

Certified since 2012 and audited annually, with a record of zero failures, recommendations or observations against the standard.

CHECK IT Health Check

An exhaustive annual penetration test by a CHECK-accredited partner, verifying the service against a determined attacker.

Cyber Essentials Plus

Hands-on, independent technical verification of our controls against internet-originated attacks.

BS7858 staff screening

Every member of Kahootz staff passes a detailed background check, because technology is only as safe as the people maintaining it.

An altogether safer cloud collaboration service

Security is built into Kahootz at every layer. Explore how, by area.

 

Encrypted in transit

All traffic uses HTTPS/SSL with TLS 1.2+ and 256-bit AES, with Forward Secrecy where the browser supports it.

Hardened against known attacks

Protected against BEAST, HEARTBLEED and POODLE; insecure SSL3 is not supported.

Encrypted at rest

Client data is encrypted with AES-256 using AWS Key Management Service, with tightly controlled keys.

Secure by API too

The same level of encryption applies when the service is accessed via the Kahootz API.

UK-based hosting

Wholly hosted, managed and supported in the UK on AWS, across multiple Availability Zones.

Resilience & redundancy

Kahootz is resilient against network, power and hardware issues, providing round-the-clock availability with a 99.95% minimum uptime guarantee.

Backups

Daily encrypted snapshots retained to a separate location for up to a month, alongside near real-time replication.

Attack protection & DR

DDoS protection via AWS Shield and WAF, and a disaster recovery programme tested annually under ISO 27001.

Secure authentication

Unique credentials per user; passwords are stored one-way encrypted and never sent by email.

Two-step verification

Optional two-step verification for Enterprise clients, for all users or a subset, by phone code or authenticator app.

Configurable password policy

Set your own rules for password length, complexity, expiry, re-use prevention, lockout and inactivity logout.

Least-privilege & audit

Role-based access that users cannot self-elevate, with full audit records available to site owners.

Screened people

BS7858-screened staff; access to client data is need-to-know only and fully audited.

Managed operations

ISO 27001 incident, configuration and change management, built on continuous improvement.

Secure development

Built to industry best practice, with each release tested by automated and manual checks.

Secure supply chain

Suppliers are appraised, contractually bound and, where possible, ISO 27001 accredited themselves.

GDPR compliant and sovereign by design

Kahootz is provided by a UK company, under UK legislation, and is protected by EU data laws — placing it outside the scope of the US Patriot Act. It is registered under the UK Data Protection Act (reference Z8289153).

Your data remains your property. We never use it or share it with third parties, and we’re committed to helping you meet your FOI and GDPR obligations.

Read: Kahootz and the GDPR

Built for OFFICIAL-SENSITIVE collaboration


Kahootz is engineered and operated in line with MOD Secure by Design principles — security is intrinsic to the architecture, not retrofitted. It helps organisations evidence their assigned Cyber Risk Profile under Def Stan 05-138, and is actively used across UK Defence for OFFICIAL-SENSITIVE collaboration.

✔️Ministry of Defence Trusted