Security
Last Updated: August 18, 2025
Security is foundational to how we build and operate KayanOS. This page describes the administrative, technical, and physical safeguards we use to protect your data. We continuously review and improve these measures as the platform evolves.
Encryption
Data is encrypted in transit using industry-standard TLS, and data at rest is encrypted on our storage layer. Sensitive credentials are never stored in plain text.
Access Control & Authentication
KayanOS enforces role-based access control, granular permissions, and scoped access so organizations decide who can view, create, edit, approve, and administer data. Access to production systems is restricted to authorized personnel on a least-privilege basis and protected by secure authentication.
Infrastructure & Hosting
Our Services run on a containerized infrastructure orchestrated with Kubernetes, with data stored on resilient, replicated storage (using technologies like Ceph). This architecture supports isolation, redundancy, and recovery.
Monitoring & Logging
We monitor our systems for availability and suspicious activity, and maintain logs to help detect, investigate, and respond to potential security events.
Digital Signatures
KayanOS includes a native digital-signature workflow: each member holds a personal signing key protected by a PIN, the server keeps only the public verification key, and every signature is cryptographically verifiable. Attachments are SHA-256 hashed and form content is captured as a signed, auditable snapshot.
Data Retention & Deletion
We retain personal information only as long as necessary for the purposes for which it was collected, and in line with our Privacy Policy. You can request deletion of organization data and the administrator account through our account-deletion process.
Responsible Disclosure
We welcome reports from the security community. If you believe you have found a vulnerability in KayanOS, please report it to us at info@rightcode.io. Please give us a reasonable opportunity to investigate and remediate before any public disclosure, and do not access or modify data that is not yours.
Contact
For any security questions or concerns, contact us at info@rightcode.io.