コンテンツへスキップ

How we protect your data

Encryption, access control, backups, and how to report a security issue.

⚠️ Pre-release notice. Kiteloom is in pre-release. This page describes our security practices as they exist today.

最終更新日 2026-08-06 · v1.0

Encryption

  • In transit — every connection to Kiteloom, including the real-time collaboration connection to a board, is encrypted (HTTPS / WSS).
  • At rest — your data is encrypted at rest by our database and file storage provider.
  • Backups — we run encrypted, off-site backups of account data on a regular schedule.

Authentication and account security

  • Passwords are checked against known-breach databases at signup.
  • Optional two-factor authentication (TOTP authenticator app, plus one-time backup codes) is available from Settings → Security.
  • Sessions are time-bounded — they refresh on activity but expire outright after 90 days, and you can review or revoke individual active sessions from Settings → Security.

Access control

Every board has an explicit visibility level (private, link-shared, or public) and every member has an explicit role (owner, editor, or viewer) — see Sharing & permissions. Permission checks happen on our servers, not just in the app you see: a viewer's write attempt is rejected server-side even if it were somehow sent, and revoking a share link disconnects everyone using it immediately rather than waiting for their session to end.

Abuse prevention

Rate limiting applies across sign-in, board creation, invites, uploads, and the real-time connection itself, to slow down automated abuse without affecting normal use.

Sub-processors

The full list of who processes data on our behalf, and why, is in the "Who we share it with" section of our Privacy Policy.

Reporting a vulnerability

If you believe you've found a security vulnerability in Kiteloom, please report it through our contact page or the machine-readable contact listed in /.well-known/security.txt. We ask that you give us a reasonable opportunity to investigate and address a report before disclosing it publicly. We commit to acknowledging any good-faith report within 5 business days.

Incident notification

If a security incident affects your personal data, we'll notify affected users within 72 hours of confirming the breach, consistent with applicable data protection law.