Security And Compliance
Security and Compliance
Last Updated: 6 September 2026
Security is core to how Kay Vault operates — especially given that every Hub goes through identity verification and we handle sensitive documents as part of that process. This page outlines the measures we take to protect your data and the Platform.
This page is a summary for transparency purposes and does not disclose specific configurations that could be used to circumvent our security measures.
- Infrastructure Security
- Self-hosted infrastructure: Kay Vault's application servers, database, and cache run on infrastructure we manage and control directly, rather than relying on third-party managed platforms for our core systems.
- Network protections: Our servers are protected by firewall rules that restrict access to only the services that need to be publicly reachable.
- Encrypted connections: All traffic between your device and Kay Vault is encrypted in transit via HTTPS/TLS.
- Isolated services: Our application layer, database, and cache run as separate, access-controlled services, limiting the blast radius of any single compromised component.
- Automated, controlled deployments: Code changes go through a controlled build-and-deploy process rather than manual, ad hoc changes to production systems.
- Application Security
- Password storage: Passwords are never stored in plain text — we store only a cryptographically hashed version.
- Authentication: We use token-based authentication (JWT) with short-lived access tokens and refresh tokens, reducing the exposure window if a token is compromised.
- Identity verification: Every Hub is manually reviewed and identity-verified before it can publish or promote content, adding a human layer of fraud prevention beyond automated checks.
- Access controls: Identity verification documents and other sensitive data are restricted to the systems and personnel that need them.
- Input validation: User-submitted data is validated and sanitized to reduce the risk of injection attacks and malformed data.
- Data Storage and Providers
We rely on a small number of vetted infrastructure providers, each scoped to a specific purpose:
| Provider | Role | Relevant Standards |
|---|---|---|
| Hetzner | Server, database, and cache hosting (self-managed) | ISO 27001-certified data centers |
| Cloudflare R2 | Media storage (images, video, audio, documents) | SOC 2, ISO 27001 |
| Resend | Transactional email delivery | Industry-standard email security practices |
| Paystack | Payment processing | PCI-DSS compliant |
We never store full payment card details ourselves — all card data is handled directly by Paystack under its PCI-DSS obligations.
- Identity Verification and Fraud Prevention
Because Kay Vault requires identity verification before a Hub can go live, we treat this process as a core security control, not just a compliance checkbox:
- Documents are reviewed before any Hub is approved to publish;
- We monitor for signs of fraudulent, duplicated, or manipulated identity submissions;
- Hubs can be suspended and re-reviewed if we later detect suspicious activity;
- We reserve the right to request re-verification at any time.
- Monitoring and Incident Response
- We monitor our systems for unusual activity, errors, and potential security events.
- In the event of a security incident affecting personal data, we will investigate promptly and notify affected users and, where legally required, relevant authorities (including the Data Protection Commission of Ghana), in accordance with applicable law.
- Security concerns or suspected vulnerabilities can be reported to [SECURITY EMAIL]. [Optional: add a responsible disclosure / bug bounty policy here if you plan to offer one.]
- Compliance
- Data protection: We aim to handle personal data in line with Ghana's Data Protection Act, 2012 (Act 843), and take reasonable steps to align with other applicable data protection frameworks where our users are located.
- Payments: Payment processing is handled by Paystack, a PCI-DSS compliant provider, so Kay Vault does not directly handle or store cardholder data.
- Identity verification: Our Hub approval process is designed to support anti-fraud and know-your-customer (KYC)-style diligence appropriate for a promotional platform, though Kay Vault is not a regulated financial institution.
- Your Role in Security
Security is a shared responsibility. You can help keep your account safe by:
- Using a strong, unique password;
- Not sharing your login credentials;
- Reporting suspicious activity or messages claiming to be from Kay Vault to [SECURITY EMAIL];
- Keeping the contact details on your account up to date, so we can reach you about account security if needed.
- Contact Us
For security questions, vulnerability reports, or compliance inquiries, contact us at support@kayvault.com.