Security & Privacy Statement
Last updated July 13, 2026
1. Encryption
Data is encrypted in transit using TLS 1.3 and at rest using AES-256. Passwords are hashed and never stored in plain text.
2. Access controls
Internal access to user data is restricted by role and logged. Two-factor authentication is available on every account, and we recommend enabling it.
3. Monitoring & incident response
We run continuous automated monitoring for unusual account activity, rate-limit authentication endpoints to slow brute-force attempts, and maintain an incident response process for investigating and disclosing any confirmed breach.
4. Vulnerability disclosure
If you’ve found a security vulnerability, please report it to security@kestrion.com rather than disclosing it publicly. We investigate all reports and will follow up directly.
5. Compliance roadmap
We currently maintain practices consistent with GDPR and CCPA requirements. A SOC 2 Type II audit is in progress; we’ll update this page once it’s complete. For how we handle your personal data specifically, see our Privacy Policy.
Other legal documents
- Privacy Policy
- Terms of Service
- Terms of Use
- Cookie Policy
- Acceptable Use Policy
- Community Guidelines
- Recruiter Code of Conduct
- Applicant Code of Conduct
- Copyright Policy (DMCA)
- Accessibility Statement
- Security & Privacy Statement
- Data Retention Policy
- Anti-Discrimination Policy
- Anti-Harassment Policy
- Equal Employment Opportunity Statement
- GDPR Privacy Notice
- CCPA Privacy Notice
- Legal Contact