1. Infrastructure Security Architecture
Kamiara is built upon a foundation of enterprise-grade cloud infrastructure. We leverage the security capabilities of Supabase Inc. and PowerSync to ensure that your financial data is protected by the same security standards used by global financial platforms.
- Certified Cloud Data Centers: Our database and storage infrastructure is hosted in SOC 2 Type II, ISO 27001, and PCI DSS compliant data centers in the European Union and the United States.
- Encryption at Rest: Database records and object storage volumes (such as receipt image files) are encrypted at rest using AES-256 encryption algorithms.
- Encryption in Transit: All data transmitted between your device, our web servers, and third-party APIs is encrypted using TLS 1.2/1.3 (HTTPS) to prevent interception or tampering.
2. Logical Data Isolation & Device Protection
We implement a Defense-in-Depth strategy across server and client environments to guarantee data privacy.
- Strict Row Level Security (RLS): Database tables enforce granular server-side Row Level Security policies. Your financial records are strictly isolated at the database engine level by your unique user identifier, preventing unauthorized access by any other user.
- Hardware-Backed On-Device Security: On mobile devices, authentication session tokens and sensitive keys are stored using Hardware-Backed Encryption (Expo SecureStore / iOS Keychain / Android Keystore), ensuring credentials never exist in plain text.
- Password Hashing: User passwords are never stored in plain text or reversible encryption; they are securely hashed using non-reversible bcrypt hashing via Supabase Auth.
3. Artificial Intelligence Privacy & Contractual Safeguards
Kamiara incorporates AI-assisted capabilities for optical character recognition (OCR) and financial coaching ("Captain Cash").
- Contractual Zero-Training Guarantee: We explicitly configure our API accounts with Google Cloud (Gemini API) and Mistral AI (La Plateforme API) with data privacy opt-out settings enforced. Customer data sent via our API requests is processed statelessly and is contractually prohibited from being used to train foundation AI models.
- PII Exclusion: Personally Identifiable Information (PII) such as real names, email addresses, raw credentials, or credit card numbers is never included in AI requests.
4. Automated Threat Prevention & Rate Limiting
We implement active technical controls to protect our API endpoints and application integrity.
- Server-Side Rate Limiting: Automated request throttling protects backend infrastructure against denial-of-service (DoS) attacks and brute-force attempts.
- Content Security Policy (CSP): Strict headers prevent Cross-Site Scripting (XSS) and unauthorized code injection on our web application.
5. Incident Response & 72-Hour Breach Notification
In accordance with GDPR requirements, Kamiara maintains a formal incident response protocol:
- 72-Hour Transparency Commitment: In the event of a confirmed security incident affecting personal data, we commit to notifying affected users via registered email within 72 hours of confirmation.
6. Security Contact & Responsible Disclosure
We welcome vulnerability disclosures from the security community. For security inquiries or to report a potential vulnerability, please contact: