Security
Security & Encryption
See how your data and payments are protected with industry-standard security practices.
Security and Encryption
This document explains how Kuata protects your identity, documents, and financial data using industry-leading encryption and security architecture. Kuata is designed from the ground up so that your personal data never leaves our secure environment without your explicit consent.
How Kuata Encrypts Your Data
Layer | Technology and Standard |
Data at rest | AES-256-GCM — the same standard used by governments and military organisations worldwide |
Data in transit | TLS 1.3 — the latest and most secure version of transport encryption; TLS 1.0 and 1.1 are blocked |
Identity verification signatures | JWS/RS256 — cryptographic signing compliant with FIPS 140-2 Level 3, the US federal standard for cryptographic modules |
Biometric data | Stored exclusively on your device hardware (iOS Secure Enclave / Android StrongBox); Kuata's servers never receive or store your fingerprint or face data |
Offline QR codes | Signed with JWS/RS256; verifiable without internet; expire after 24 hours by default |
Keys and secrets | Managed by AWS Key Management Service (KMS) with hardware security modules (HSMs) |
Zero-Knowledge Verification
When you share your identity with a bank, employer, or government agency through Kuata, the verifying organisation receives only a cryptographic pass/fail result — nothing else. Your name, ID number, date of birth, and document images are never transmitted to them.
What the verifier receives | What the verifier does NOT receive |
verified: true or false | Your name or date of birth |
Timestamp of the verification | Your national ID number |
A unique request ID | Any document image or scan |
Your explicit consent record | Your address or contact details |
Note: This design is called zero-knowledge architecture. Even if a verifying organisation's systems were ever compromised, there is no personal data to steal from the verification result itself. |
Infrastructure Security
Control | Implementation |
Cloud infrastructure | Amazon Web Services (AWS) — Kuata's data is hosted in regionally appropriate AWS data centres |
Network isolation | Virtual Private Cloud (VPC) with private subnets; no direct internet access to data processing workloads |
Access control | Role-based access control (RBAC); principle of least privilege; multi-factor authentication for all staff |
Threat monitoring | AWS GuardDuty (threat detection) and AWS CloudTrail (immutable access logging) active at all times |
Intrusion detection | Real-time anomaly detection on all API traffic |
Penetration testing | Annual third-party penetration test by an independent security firm; critical findings remediated before deployment |
Vulnerability management | All software dependencies scanned continuously; critical CVEs patched within 48 hours of disclosure |
Immutable Audit Trail
Every action taken on your Kuata account — logins, document verifications, payments, PIN changes, and consent decisions — is logged in a tamper-proof audit trail. You can view your own activity log at any time from Settings -> Privacy -> Activity log. The log cannot be altered by anyone, including Kuata staff.
Certifications and Standards
Standard / Certification | Status |
FIPS 140-2 Level 3 — Cryptographic Module Validation | Active — applied to all identity signing operations |
ISO/IEC 27001:2022 — Information Security Management | Certification in progress |
SOC 2 Type II — Security, Availability and Confidentiality | Audit in progress |
PCI DSS Level 1 — Payment Card Industry Data Security | Assessment in progress |
OWASP Mobile Top 10 — Mobile App Security | All risks addressed in development and testing |
OWASP API Security Top 10 | All risks addressed in API design and testing |
Data Residency
Kuata stores and processes your data in the AWS region closest to your country of residence, keeping it subject to local data protection laws. Enterprise and government customers can request dedicated single-region or on-premises deployments for complete data sovereignty.
What Kuata Will Never Do
Security Alert: Kuata will never ask for your PIN, password, biometric, or one-time code by phone, SMS, or email. If you receive a request like this claiming to be from Kuata, it is a scam — do not respond, and report it immediately to security@kuata.io. |
• We never store your biometric data on our servers
• We never sell your data to advertisers or data brokers
• We never share your personal data with verification requesters
• We never transmit your full document images to third parties
• We never disable encryption to accommodate a request, regardless of who makes it
Reporting a Security Issue
If you discover a security vulnerability in Kuata, please report it responsibly to security@kuata.io. Include a description of the issue and steps to reproduce it. We will acknowledge all reports within 24 hours and provide an initial assessment within 5 business days. We do not take legal action against good-faith security researchers.