Security and Compliance
Built on a foundation of security and trust
The Kahua platform is designed to meet or exceed internationally recognized security standards, letting teams deliver every project with confidence.
FedRAMP certified
Keep sensitive construction data inside an environment trusted for federal work. The Kahua Government Network features active FedRAMP Class C Certification and DoD IL-2 authorization, maintaining a trusted compliance standard since 2022.
GovRAMP authorized
For public-sector teams that need governed cloud security for capital programs, the Kahua Government Network is GovRAMP Moderate authorized. The same environment also holds TX-RAMP authorization at the state level.
CMMC aligned
For teams working on DoD-related work, Kahua supports CMMC-aligned workflows that help protect CUI across project records, approvals, and partner access.
SOC 2 Type 2 report available
Kahua supports security and procurement reviews with SOC 2 Type 2 documentation, allowing teams to evaluate the platform with confidence while maintaining the controls needed for secure project delivery.
ISO 27001 certified
Kahua’s ISO 27001 certification gives IT, security, and compliance teams confidence in the platform’s mature information security program built to help protect sensitive project data.
Cyber Essentials Plus aligned
For organizations in the U.K., the Kahua platform gives teams a secure way to work in a protected environment with governed workflows, access controls, and traceable activity across the full project record.
Data Privacy
Committed to consumer data privacy across borders
Manage your global capital programs inside Kahua with privacy practices that address regional data protection requirements, including GDPR, CCPA, and the EU-U.S. Data Privacy Framework.



Kahua AI™ operates inside Kahua’s secure, governed environment.
Which means project data stays protected inside the platform, with access controls, audit trails, and security boundaries designed to keep sensitive information under customer control.
Explore Kahua AI





FAQs
Frequently asked questions
Kahua protects stored data using AES-256 encryption and data in transit using TLS 1.2 or higher. Role-based access controls restrict what users can see and do, and multifactor authentication is enforced where applicable.
Specific hosting, access, and compliance requirements can be addressed during security and implementation planning.
Kahua supports security and compliance requirements for enterprise, government, and regulated organizations. Current programs include FedRAMP Class C Certification, GovRAMP authorization, ISO 27001 certification, and SOC 2 compliance.
Kahua uses role-based access controls to help ensure users only see and act on the information relevant to their role. Multifactor authentication is enforced where applicable, adding another layer of protection for access to the platform.
Noa and Kahua AI operate inside the Kahua platform, so AI-assisted work follows the platform’s existing permissions, governance, and security controls. Kahua has also received approval to support AI capabilities within its FedRAMP-certified environment.