Security is core to how Kalsoni is built, not an afterthought. Here's how we protect your account and business data.
All traffic to and from Kalsoni is encrypted using HTTPS/TLS, protecting your data as it moves between your device and our servers.
Where you connect third-party services — such as your M-Pesa Daraja API credentials — those credentials are encrypted at rest using industry-standard encryption (Fernet symmetric encryption) before being stored. They are never stored or logged in plain text.
Passwords are never stored in plain text. Failed login attempts are monitored, and accounts can be automatically locked after repeated failed attempts to prevent brute-force access.
Kalsoni is multi-tenant by design: every business's data is strictly scoped to that business's account. Application-level checks ensure one business can never view or access another business's records.
Kalsoni runs on securely configured cloud infrastructure with access restricted to authorized personnel only. Regular backups help ensure business continuity in case of unexpected incidents.
If you believe you've found a security vulnerability in Kalsoni, please report it to hello@kalsoni.io before disclosing it publicly. We take all reports seriously and will respond promptly.
Security is a shared responsibility. Please use a strong, unique password for your Kalsoni account, avoid sharing login credentials between team members, and remove access promptly for staff who leave your business.