← Back to KinKeep

Your Data, Protected

KinKeep is built for families managing sensitive caregiving information. We implement industry-standard protections at every layer.

AES-256 Encryption
Read-Only Bank Access
SOC 2 Infrastructure
Your Data Is Never Sold

Data Encryption

All data encrypted in transit with TLS and at rest with AES-256-GCM. Passwords hashed with bcrypt (12 rounds) — we never store plaintext.

Authentication & Sessions

HTTP-only JWT cookies with 7-day expiry. Rate-limited endpoints. HSTS, CSP, X-Frame-Options, and nosniff headers on every response.

Infrastructure

Hosted on Vercel with managed PostgreSQL. Our infrastructure providers maintain SOC 2 Type II compliance and undergo regular security audits.

Access Control

Role-based permissions ensure caregivers only see profiles they're invited to. Full audit logging tracks every access and change.

Financial Data

Bank connections via Plaid use read-only tokens. We never store credentials. Tokens are revoked immediately on account deletion.

Data Retention & Deletion

Account deletion triggers a hard delete after a 30-day grace period — Plaid tokens revoked, documents purged, audit logs anonymized.

Vulnerability Reporting

Found something? We take every report seriously. Reach out responsibly and we'll respond promptly.

Found a vulnerability?

We take every report seriously. If you discover a security issue, please disclose it responsibly.

security@trykinkeep.com
For full details on how we handle your data, see our Privacy Policy or our Financial Data Security Policy.