Security practices designed for finance teams.
KAAASH is built around controlled access, tenant separation, auditability and secure processing of financial reporting data.
Security Overview
This page explains, in plain language, how we protect customer data. For enterprise customers, we can provide a more detailed security and implementation pack on request.
Security principles
- Least privilege: access is granted only where needed to operate, support or secure the service.
- Tenant separation: customer data is logically separated by workspace and tenant controls.
- Auditability: key administrative and product activities can be logged for accountability.
- Secure-by-design workflows: product flows are designed around controlled data handling and finance review needs.
Hosting & infrastructure
- Application hosted on reputable cloud infrastructure providers.
- HTTPS enforced across public endpoints.
- Infrastructure access restricted to authorized personnel.
- Production configuration reviewed before major deployment changes.
Data protection
- Encryption in transit: HTTPS/TLS is used for data transmitted between your browser and our services.
- Encryption at rest: storage and database-level encryption is used where supported by infrastructure providers.
- Backups: routine backup and disaster recovery practices are maintained based on hosting and service tier.
- Data minimization: we collect and process information needed to operate, support and secure the service.
Access control
- Role-based access controls for customer workspaces.
- User invitations controlled by workspace administrators and plan entitlements.
- User limits and subscription entitlements enforced inside the application.
- Administrative activities can be tracked through audit logs.
Application security
- Authentication handled through secure identity and session flows.
- Input validation on user-submitted data and uploaded lease information.
- Tenant-aware application logic to prevent unauthorized cross-workspace access.
- Security headers, CORS controls and environment-based configuration used in production deployment.
Payments
Card payments are processed by Stripe where available. KAAASH does not store full card details. For enterprise customers, invoice or bank-transfer billing may be arranged separately.
Monitoring & reliability
- Platform logs and operational monitoring are used to investigate errors and availability issues.
- Deployment changes are tested before release where practical.
- Critical service issues are reviewed and prioritized based on customer impact.
Business continuity
- Routine backups of critical application data.
- Disaster recovery procedures appropriate to service tier and infrastructure provider capability.
- Monitoring and alerting for platform availability and operational issues.
Enterprise security requests
Enterprise customers may request additional security information during onboarding, including hosting overview, data handling approach, access control summary and implementation support details.
Reporting vulnerabilities
If you discover a security issue, please report it via the Contact page. We appreciate responsible disclosure and will review reported issues in good faith.