Archives 2025/06

Protocol level integrity guarantees in Kafka

I was recently asked to design a method to meet ITAC (IT Application Controls) standards for critical data flows in our organisation. ITAC are application-level controls looking mainly at how we ensure the completeness, accuracy and validity of transactions - for example, invoices or trades. Our control set is based on the ICFR principles, of which ITAC is one part.

The specific control objective I was asked to look at relates to the risk of loss of integrity of financial data transfers. The focus on the integrity of the data, not authenticity or non-repudiation is really important as it means cryptographic solutions aren’t required - Kafka’s native protocol features can satisfy the requirements.