Security and compliance

Kana collects evidence from endpoints for Japan's supply-chain security (SCS) scheme. This page is for the people who have to sign off on it: your head-office security team, your auditor, your customer's vendor-risk desk. It says what the evidence maps to, where it lives, and what the agent actually does. It does not claim certifications Kana does not hold.

What we do and do not claim

Control mapping

SOC 2 references are to the 2017 Trust Services Criteria, common criteria series CC6 (logical and physical access), CC7 (system operations) and CC8 (change management). ISO references are to Annex A of ISO/IEC 27001:2022. "Full" means the agent produces the evidence on its own. "Part" means the agent produces some of it and a person writes the rest.

Evidence Kana collects, and the controls it supports
What the control asksSOC 2ISO 27001What Kana's evidence shows
Asset inventoryCC6.1A.5.9, A.8.1Every device, its OS and its installed applications, inventoried daily. Full.
Disk encryptionCC6.1, CC6.7A.8.24, A.8.1Encryption on or off, per device, per day. Full.
Screen lockCC6.1A.7.7, A.8.1Screen lock enabled, per device, per day. Full.
Accounts and privilegesCC6.1, CC6.2, CC6.3A.5.15, A.5.18, A.8.2Local accounts and administrator rights on each device. Permissions inside your business systems still need a human check. Part.
Malware protectionCC6.8A.8.7Whether malware protection is present and running on each device. On the Protection plan, EPP/EDR detection and isolation records as well. Full.
Patching and vulnerabilitiesCC7.1, CC8.1A.8.8Missing OS and software updates found and applied. The date each one landed is kept as evidence. Full.
LoggingCC7.2A.8.15Device activity logs retained. You can show the retention period was met. Full.
Monitoring and security eventsCC7.2, CC7.3A.8.16Detection is automatic. Deciding what an event means is people's work; the Monitored plan supplies the people, in Japanese, nights and weekends included. Part.
Incident responseCC7.3, CC7.4, CC7.5A.5.24, A.5.26On the Protection plan, detection, isolation and recovery are automatic and recorded. The call list and the procedure are yours; we hand you a template. Part.
Change managementCC8.1A.8.32A dated record of each update applied, and a daily inventory, so a change in a device's software shows up the next day. Approvals are yours. Part.
Awareness and trainingoutside CC6–CC8A.6.3Not collected. Naming an owner, running training and doing internal audit is human work; the coverage table on the home page says the same.

What an endpoint agent cannot evidence: governance, risk assessment, vendor management, HR controls, policy. In SOC 2 terms that is CC1 to CC5 and CC9; in Annex A it is most of the organizational and people controls. It is about half of the work, and it is people and policy. The home page says the same thing in fewer words.

Where the data is

Evidence and logs are stored in Japan. Support and monitoring are in Japanese.

The EPP/EDR core is licensed from Endpoint Solutions, Inc. in the United States. The collection agent is an open-source implementation built on osquery.

Assessor accounts are available: an assessor, a customer or your own auditor can be given their own account to view the evidence, or you hand them the exported PDF. Either way the manual register goes away.

What the agent runs

osquery exposes device state as SQL tables. Every query Kana runs against those tables is published as a config file, and you get it before rollout. If a query is not in the file, the agent does not run it. There are no hidden commands.

Because the queries are readable, your security team can answer the question "what does this thing collect?" from the source rather than from a sales deck.

Running alongside what you have

Start with the free star check