Security

Security & Encryption

See how your data and payments are protected with industry-standard security practices.

Security and Encryption

This document explains how Kuata protects your identity, documents, and financial data using industry-leading encryption and security architecture. Kuata is designed from the ground up so that your personal data never leaves our secure environment without your explicit consent.

 

How Kuata Encrypts Your Data


Layer


Technology and Standard


Data at rest


AES-256-GCM — the same standard used by governments and military organisations worldwide


Data in transit


TLS 1.3 — the latest and most secure version of transport encryption; TLS 1.0 and 1.1 are blocked


Identity verification signatures


JWS/RS256 — cryptographic signing compliant with FIPS 140-2 Level 3, the US federal standard for cryptographic modules


Biometric data


Stored exclusively on your device hardware (iOS Secure Enclave / Android StrongBox); Kuata's servers never receive or store your fingerprint or face data


Offline QR codes


Signed with JWS/RS256; verifiable without internet; expire after 24 hours by default


Keys and secrets


Managed by AWS Key Management Service (KMS) with hardware security modules (HSMs)

 

Zero-Knowledge Verification

When you share your identity with a bank, employer, or government agency through Kuata, the verifying organisation receives only a cryptographic pass/fail result — nothing else. Your name, ID number, date of birth, and document images are never transmitted to them.

 


What the verifier receives


What the verifier does NOT receive


verified: true or false


Your name or date of birth


Timestamp of the verification


Your national ID number


A unique request ID


Any document image or scan


Your explicit consent record


Your address or contact details

 


Note:

This design is called zero-knowledge architecture. Even if a verifying organisation's systems were ever compromised, there is no personal data to steal from the verification result itself.

 

Infrastructure Security


Control


Implementation


Cloud infrastructure


Amazon Web Services (AWS) — Kuata's data is hosted in regionally appropriate AWS data centres


Network isolation


Virtual Private Cloud (VPC) with private subnets; no direct internet access to data processing workloads


Access control


Role-based access control (RBAC); principle of least privilege; multi-factor authentication for all staff


Threat monitoring


AWS GuardDuty (threat detection) and AWS CloudTrail (immutable access logging) active at all times


Intrusion detection


Real-time anomaly detection on all API traffic


Penetration testing


Annual third-party penetration test by an independent security firm; critical findings remediated before deployment


Vulnerability management


All software dependencies scanned continuously; critical CVEs patched within 48 hours of disclosure

 

Immutable Audit Trail

Every action taken on your Kuata account — logins, document verifications, payments, PIN changes, and consent decisions — is logged in a tamper-proof audit trail. You can view your own activity log at any time from Settings -> Privacy -> Activity log. The log cannot be altered by anyone, including Kuata staff.

 

Certifications and Standards


Standard / Certification


Status


FIPS 140-2 Level 3 — Cryptographic Module Validation


Active — applied to all identity signing operations


ISO/IEC 27001:2022 — Information Security Management


Certification in progress


SOC 2 Type II — Security, Availability and Confidentiality


Audit in progress


PCI DSS Level 1 — Payment Card Industry Data Security


Assessment in progress


OWASP Mobile Top 10 — Mobile App Security


All risks addressed in development and testing


OWASP API Security Top 10


All risks addressed in API design and testing

 

Data Residency

Kuata stores and processes your data in the AWS region closest to your country of residence, keeping it subject to local data protection laws. Enterprise and government customers can request dedicated single-region or on-premises deployments for complete data sovereignty.

 

What Kuata Will Never Do


Security Alert:

Kuata will never ask for your PIN, password, biometric, or one-time code by phone, SMS, or email. If you receive a request like this claiming to be from Kuata, it is a scam — do not respond, and report it immediately to security@kuata.io.

 

• We never store your biometric data on our servers

• We never sell your data to advertisers or data brokers

• We never share your personal data with verification requesters

• We never transmit your full document images to third parties

• We never disable encryption to accommodate a request, regardless of who makes it

 

Reporting a Security Issue

If you discover a security vulnerability in Kuata, please report it responsibly to security@kuata.io. Include a description of the issue and steps to reproduce it. We will acknowledge all reports within 24 hours and provide an initial assessment within 5 business days. We do not take legal action against good-faith security researchers.

Need help? Contact Support

Questions? Contact Sales

On this page

© 2026 Kuata All rights reserved.
English

Create a free website with Framer, the website builder loved by startups, designers and agencies.