Security
Last updated: August 21, 2026
1. How We Protect the Service
- Encryption — traffic to and from the Service is encrypted in transit over TLS, and data is encrypted at rest by our infrastructure providers.
- Session-based authentication — accounts are accessed through short-lived sessions; signing out invalidates the session server-side.
- Identity verification — where KYC/AML checks appear, they run through a banking-sandbox provider during pre-alpha and a regulated partner at launch.
- Transparency by design — every vault movement is visible to every member of a family, so unauthorized activity has nowhere to hide.
2. Data Handling During Pre-Alpha
Pre-alpha data is test data. It may be reset or deleted as we develop, and it is covered by the safeguards described in our Privacy Policy. Because no test environment can guarantee perfect security, the standing rule applies: placeholder information only — no real Social Security numbers, card numbers, bank details, or ID documents.
3. Reporting a Vulnerability
If you believe you have found a security vulnerability in KinVest, please report it to security@kinvestapp.com with a description of the issue and steps to reproduce it. We ask that you:
- Give us a reasonable window to investigate and fix the issue before any public disclosure.
- Avoid accessing, modifying, or deleting data belonging to other users.
- Avoid disrupting the Service (no denial-of-service testing or automated scanning that degrades availability).
We take every report seriously and will acknowledge legitimate submissions as quickly as a small pre-alpha team can. We will not pursue legal action against good-faith security research that follows these guidelines.
4. What We Ask of You
- Keep your password private and unique to KinVest.
- Sign out on shared devices.
- Tell us immediately at security@kinvestapp.com if you suspect someone else has accessed your account.