Security

Your data is safe.
We can prove it.

KinPass holds some of the most sensitive data that exists — medical histories, behavioral vulnerabilities, and emergency information about people who depend on others. We built security into the foundation, not bolted on after the fact.

End-to-End Encryption

All care data is encrypted at rest using AES-256 and in transit using TLS 1.3. Your data is unreadable to anyone who doesn't have the keys — including us.

HIPAA-Eligible Infrastructure

KinPass runs on Google Firebase, which is HIPAA-eligible. We offer Business Associate Agreements (BAAs) for enterprise and healthcare customers.

Role-Based Access Control

Every caregiver has an explicit permission level you set. They see only what you authorize. Nothing more. You can change or revoke access in seconds.

Complete Audit Trail

Every login, every profile view, every data change, and every handoff is logged with a timestamp. Full accountability for every event.

Secure Authentication

Firebase Authentication with email verification, secure token handling, and optional biometric login (Face ID / Touch ID). No passwords stored in plaintext.

Secure Infrastructure

Hosted on Google Cloud (Firebase Blaze), one of the most secure and reliable cloud platforms in the world. Automatic backups. 99.95% uptime SLA.

Compliance

Meeting the standards that matter in care.

HIPAA Active

HIPAA-eligible infrastructure. BAA available for enterprise customers. All PHI handled according to HIPAA requirements.

FERPA Active

Student educational records and care information handled in compliance with FERPA for school and education customers.

COPPA Active

Platform used by adults to manage care for children. Children under 13 cannot create accounts. Parental consent model enforced.

SOC 2 Type II In Progress

SOC 2 Type II certification in progress. Expected completion for enterprise customers. Contact us for current security documentation.

GDPR Planned

Data protection rights honored globally. GDPR compliance framework in development for international expansion.

ISO 27001 Planned

Information security management system implementation planned as part of our enterprise compliance roadmap.

Our data practices

We never sell your data
Your care profile information is never sold to third parties, advertisers, or data brokers. Period.
AI doesn't train on your data
Your care conversations with the AI Assistant are used to answer your questions only. They are never used to train AI models.
You control your data
You can export all your care data at any time and delete your account permanently. Your data belongs to you.
Minimal data collection
We collect only what's needed to provide the service. We don't collect location data, behavioral tracking, or advertising identifiers.
Breach notification
In the unlikely event of a data breach, we will notify affected users within 72 hours and provide full transparency about what happened.

Questions about our security practices?

[loading security email...]