New

Now in Claude, ChatGPT, Cursor & more with our MCP server

Koji Compliance

Koji Compliance hub.

Everything InfoSec, Legal, and Procurement need to evaluate Koji for enterprise deployment. Self-serve where possible, gated where the contract requires it, with a one-business-day response window for everything else.

Last updated: May 2026Applies to: Koji B.V. (Netherlands)

Forwarding this to your security or legal team?

Send the right document bundle in one click. We email your team a branded summary, route replies back to you, and copy Koji compliance so we can follow up if helpful.

GDPR + UK GDPR compliant20 US state privacy laws coveredEU SCCs + UK Addendum incorporatedDPA ready to counter-signHIPAA on enterprise tierISO 42001-alignedSOC 2 Type II + ISO 27001 on roadmap

What's in this hub.

Koji is operated by Koji B.V., a Dutch private company. The contracting entity for every enterprise deployment is the same, regardless of where the customer is located. Customer data can be provisioned in either the European Union or the United States, depending on the residency option selected at contract signing.

This hub holds the documentation that comes up first in enterprise evaluation, organized into seven groups: an at-a-glance coverage matrix, legal contracts, security controls, regional privacy programs, sectoral frameworks, AI governance and accessibility, plus downloadable resources. Anything not published here is available by emailing our compliance team.

Where are you based?Filters the docs to show what applies to you. Global docs always appear.

Overview

The 30-second answer to 'do you cover everything we need?'

Legal & contracts

Everything procurement and legal teams need to evaluate the relationship.

Security & operations

Technical controls, infrastructure, and the procedures behind them.

Regional privacy

The privacy regime that applies in your region. The same Koji program satisfies all of them; the documentation flexes per jurisdiction.

Sectoral & industry

Sector-specific frameworks for healthcare, financial services, cybersecurity, education, and payments.

AI governance & accessibility

How Koji approaches AI responsibility and accessible product design.

Resources

Downloads, contacts, and request flows.

Have a question we haven't answered?

Email [email protected] for legal or DPA questions, [email protected] for security questionnaires and incident reports, and [email protected] for data-subject requests and privacy concerns. Standard response window is one business day.

See all compliance contacts
Questions about this document? Contact compliance.Back to compliance hub