KinPass holds some of the most sensitive data that exists — medical histories, behavioral vulnerabilities, and emergency information about people who depend on others. We built security into the foundation, not bolted on after the fact.
All care data is encrypted at rest using AES-256 and in transit using TLS 1.3. Your data is unreadable to anyone who doesn't have the keys — including us.
KinPass runs on Google Firebase, which is HIPAA-eligible. We offer Business Associate Agreements (BAAs) for enterprise and healthcare customers.
Every caregiver has an explicit permission level you set. They see only what you authorize. Nothing more. You can change or revoke access in seconds.
Every login, every profile view, every data change, and every handoff is logged with a timestamp. Full accountability for every event.
Firebase Authentication with email verification, secure token handling, and optional biometric login (Face ID / Touch ID). No passwords stored in plaintext.
Hosted on Google Cloud (Firebase Blaze), one of the most secure and reliable cloud platforms in the world. Automatic backups. 99.95% uptime SLA.
HIPAA-eligible infrastructure. BAA available for enterprise customers. All PHI handled according to HIPAA requirements.
Student educational records and care information handled in compliance with FERPA for school and education customers.
Platform used by adults to manage care for children. Children under 13 cannot create accounts. Parental consent model enforced.
SOC 2 Type II certification in progress. Expected completion for enterprise customers. Contact us for current security documentation.
Data protection rights honored globally. GDPR compliance framework in development for international expansion.
Information security management system implementation planned as part of our enterprise compliance roadmap.
Questions about our security practices?
[loading security email...]