Kana collects evidence from endpoints for Japan's supply-chain security (SCS) scheme. This page is for the people who have to sign off on it: your head-office security team, your auditor, your customer's vendor-risk desk. It says what the evidence maps to, where it lives, and what the agent actually does. It does not claim certifications Kana does not hold.
SOC 2 references are to the 2017 Trust Services Criteria, common criteria series CC6 (logical and physical access), CC7 (system operations) and CC8 (change management). ISO references are to Annex A of ISO/IEC 27001:2022. "Full" means the agent produces the evidence on its own. "Part" means the agent produces some of it and a person writes the rest.
| What the control asks | SOC 2 | ISO 27001 | What Kana's evidence shows |
|---|---|---|---|
| Asset inventory | CC6.1 | A.5.9, A.8.1 | Every device, its OS and its installed applications, inventoried daily. Full. |
| Disk encryption | CC6.1, CC6.7 | A.8.24, A.8.1 | Encryption on or off, per device, per day. Full. |
| Screen lock | CC6.1 | A.7.7, A.8.1 | Screen lock enabled, per device, per day. Full. |
| Accounts and privileges | CC6.1, CC6.2, CC6.3 | A.5.15, A.5.18, A.8.2 | Local accounts and administrator rights on each device. Permissions inside your business systems still need a human check. Part. |
| Malware protection | CC6.8 | A.8.7 | Whether malware protection is present and running on each device. On the Protection plan, EPP/EDR detection and isolation records as well. Full. |
| Patching and vulnerabilities | CC7.1, CC8.1 | A.8.8 | Missing OS and software updates found and applied. The date each one landed is kept as evidence. Full. |
| Logging | CC7.2 | A.8.15 | Device activity logs retained. You can show the retention period was met. Full. |
| Monitoring and security events | CC7.2, CC7.3 | A.8.16 | Detection is automatic. Deciding what an event means is people's work; the Monitored plan supplies the people, in Japanese, nights and weekends included. Part. |
| Incident response | CC7.3, CC7.4, CC7.5 | A.5.24, A.5.26 | On the Protection plan, detection, isolation and recovery are automatic and recorded. The call list and the procedure are yours; we hand you a template. Part. |
| Change management | CC8.1 | A.8.32 | A dated record of each update applied, and a daily inventory, so a change in a device's software shows up the next day. Approvals are yours. Part. |
| Awareness and training | outside CC6–CC8 | A.6.3 | Not collected. Naming an owner, running training and doing internal audit is human work; the coverage table on the home page says the same. |
What an endpoint agent cannot evidence: governance, risk assessment, vendor management, HR controls, policy. In SOC 2 terms that is CC1 to CC5 and CC9; in Annex A it is most of the organizational and people controls. It is about half of the work, and it is people and policy. The home page says the same thing in fewer words.
Evidence and logs are stored in Japan. Support and monitoring are in Japanese.
The EPP/EDR core is licensed from Endpoint Solutions, Inc. in the United States. The collection agent is an open-source implementation built on osquery.
Assessor accounts are available: an assessor, a customer or your own auditor can be given their own account to view the evidence, or you hand them the exported PDF. Either way the manual register goes away.
osquery exposes device state as SQL tables. Every query Kana runs against those tables is published as a config file, and you get it before rollout. If a query is not in the file, the agent does not run it. There are no hidden commands.
Because the queries are readable, your security team can answer the question "what does this thing collect?" from the source rather than from a sales deck.