Security

How we protect your business data

Security is core to how Kalsoni is built, not an afterthought. Here's how we protect your account and business data.

Encryption in Transit

All traffic to and from Kalsoni is encrypted using HTTPS/TLS, protecting your data as it moves between your device and our servers.

Sensitive Credential Encryption

Where you connect third-party services — such as your M-Pesa Daraja API credentials — those credentials are encrypted at rest using industry-standard encryption (Fernet symmetric encryption) before being stored. They are never stored or logged in plain text.

Password Security

Passwords are never stored in plain text. Failed login attempts are monitored, and accounts can be automatically locked after repeated failed attempts to prevent brute-force access.

Data Isolation

Kalsoni is multi-tenant by design: every business's data is strictly scoped to that business's account. Application-level checks ensure one business can never view or access another business's records.

Infrastructure

Kalsoni runs on securely configured cloud infrastructure with access restricted to authorized personnel only. Regular backups help ensure business continuity in case of unexpected incidents.

Responsible Disclosure

If you believe you've found a security vulnerability in Kalsoni, please report it to hello@kalsoni.io before disclosing it publicly. We take all reports seriously and will respond promptly.

Your Role

Security is a shared responsibility. Please use a strong, unique password for your Kalsoni account, avoid sharing login credentials between team members, and remove access promptly for staff who leave your business.