YOUR SECURITY IS OUR PRIORITY.
KINETIQ is built on enterprise-grade cloud infrastructure with security practices designed for financial and identity-based platforms.
Security Notice details and review schedule
Notice Details
- Effective Date: August 3, 2026
- Version: 1.0
- Document Owner: KINETIQ Operations
- Next Scheduled Review: August 3, 2027
Security by design
Cloud Foundation
Google Cloud infrastructure provides reliability, scalability, and built-in security features.
Encryption
HTTPS end-to-end encryption protects all data in transit between your device and our servers.
Access Control
Role-based access controls (RBAC) ensure only authorized personnel can access sensitive systems.
Identity Verification
Secure identity verification integrations protect your account and personal information.
Multi-layered protection
Our Commitment
- Immutable audit logging records all system activities
- Rate limiting and abuse protection prevent unauthorized access
- Environment separation between staging and production ensures safe testing
- Encrypted secret management protects sensitive credentials
- Continuous monitoring and observability tooling detect threats in real-time
Deployment Strategy
We follow a phased deployment model, meaning all systems are tested extensively in staging before production release. This approach ensures stability, reliability, and security across all member interactions.
This multi-step testing process reduces risk and provides confidence that every update meets our security and operational standards.
Operational response to security events
Incident Response
- Security events are triaged, documented, and escalated through internal response procedures
- Access may be restricted, credentials rotated, or affected systems isolated during investigation
- Internal teams coordinate containment, remediation, recovery, and post-incident review
- Incident records are maintained to support accountability, lessons learned, and operational improvements
Notification timing and disclosure standards
Breach Notification Timelines
- Notify applicable regulatory authorities within 72 hours of becoming aware of the breach, where required by applicable law
- Notify affected users within 30 calendar days of breach confirmation, except where law enforcement requests a delay
- Notification will include the nature of the incident, categories of data affected, likely consequences, measures taken or proposed to address the incident, and a designated contact for further information
- Where KINETIQ determines that a breach is unlikely to result in risk to individual rights and freedoms, notification may be limited to internal incident documentation
Baseline technical controls applied across the Platform
Technical Security Standards
- Encryption in transit: TLS 1.2 or higher on all client-server communications
- Encryption at rest: AES-256 for sensitive data fields stored in Platform databases
- Authentication: Firebase Authentication with multi-factor authentication available
- Access controls: Role-based access control (RBAC) enforced at the API layer; principle of least privilege applied to all internal systems
- Audit logging: All privileged actions, governance events, and account modifications are logged with requestId, timestamp, and actor identity
- Rate limiting: API rate limiting applied to all endpoints to mitigate automated abuse
- Dependency management: Third-party dependencies reviewed for known vulnerabilities on a regular basis
How independent researchers can report vulnerabilities
Responsible Disclosure
KINETIQ welcomes responsible disclosure of security vulnerabilities from independent security researchers.
If you believe you have identified a security vulnerability in the KINETIQ Platform:
- Do not publicly disclose the vulnerability before contacting KINETIQ
- Submit your finding to: [INSERT LEGAL EMAIL ADDRESS] with the subject line "Security Vulnerability Report"
- Include: description of the vulnerability, steps to reproduce, potential impact, and your contact information
- KINETIQ commits to acknowledging receipt within 5 business days, investigating all credible reports, and notifying the reporter of resolution where legally permissible
KINETIQ does not pursue legal action against researchers who comply with this policy and act in good faith.
Providers operating under contractual data processing agreements
Third-Party Security Providers
- Firebase / Google Cloud - authentication, database hosting, and infrastructure
- Persona - identity verification (KYC) data processing
- Sentry - error monitoring and application diagnostics
- [INSERT PAYMENT PROCESSOR] - payment processing (where applicable)
Each provider is contractually obligated to implement security controls appropriate to the sensitivity of data processed. KINETIQ reviews provider security posture prior to onboarding and on a periodic basis thereafter.
The Reality of Security
No platform can claim to be "100% secure." The digital landscape evolves constantly, and security is an ongoing process, not a destination.
However, security, compliance, and operational resilience are core priorities in KINETIQ's architecture and deployment strategy. We invest continuously in protection, monitoring, and improvement.
Your trust matters to us. We're committed to protecting your data and privacy at the highest standards.
Security-related reporting and general inquiries
Security Contact
For security-related inquiries, breach notifications, or vulnerability reports:
Email: [INSERT LEGAL EMAIL ADDRESS]
Subject Line: "Security Notice - [Nature of Inquiry]"
For governance and general Platform inquiries:
[INSERT CONTACT URL]
Outside Legal Counsel:
Foley & Lardner LLP - Clyde Tinnen, Partner
777 East Wisconsin Avenue, Milwaukee, WI 53202-5306
Phone: 414.297.5026
(Disclosure of counsel does not designate counsel as service-of-process agent)