1. Our approach
We are a small team and we keep security practical. Below is what we actually do. We list controls, not slogans, and we do not claim certifications we do not hold. We do not currently hold SOC 2, ISO 27001 or similar certifications.
2. Controls in place
Encrypted in transit
All pages and API calls use HTTPS. Session cookies are marked secure and their contents are encrypted.
Safer sign-in
Passwords are stored hashed, never in readable form. Repeated sign-in attempts are rate-limited, and new passwords are checked against lists of known breached passwords.
Separate staff and client access
The team app and the client portal use separate sign-ins and sessions. A portal customer can only see records that belong to them.
Roles and scoped tokens
Team roles control who can change records. API tokens are read-only unless write access is explicitly granted, and can be revoked at any time.
Ledger integrity
Records post to a double-entry ledger. Posted entries are voided by a reversing entry, not erased, preserving an audit trail.
Safer integrations
Outbound webhooks are checked so they cannot be pointed at internal network addresses.
Controlled server access
Administrative access to the servers uses individual keys, and each connection is logged with the key, time and source.
Review before posting
Records drafted by document scanning are created as drafts for a person to confirm. They are not posted automatically.
3. What you can do
- Use a strong, unique password and keep it private.
- Give each person their own account, and remove people who no longer need access.
- Create API tokens with the least access needed, and revoke ones you no longer use.
- Review who has write access, and check your records regularly.
4. Reporting a vulnerability
If you believe you have found a security issue, please email billing@krumart.com with “Security report” in the subject and enough detail to reproduce it. Please:
- Give us reasonable time to fix the issue before telling anyone else.
- Do not access, change or delete data that is not yours, and do not disrupt the Service.
- Do not use social engineering, or test physical or third-party systems.
We will acknowledge good-faith reports, work to fix valid issues, and will not take legal action against research that follows these guidelines.
5. If something goes wrong
If we confirm an incident that affects your information, we will tell the affected business without undue delay and share what we know, in line with applicable law.