Security at Kang Workspace

The controls below ship with every workspace today. This page is maintained by the Kang team and does not represent a third-party certification.

Access controls

  • Workspace-scoped permissions on every read and write
  • Role-based team management (owner, admin, member)
  • Per-workspace permission templates for common team shapes
  • Sign-in via password or Google, with optional route protection

Data protection

  • HTTPS with modern TLS for all traffic
  • Row-level security enforced at the database
  • Signed URLs for private storage assets
  • Least-privilege service accounts for backend operations

Audit & traceability

  • Every HR approval records actor, timestamp and outcome
  • Chat message edits and deletes are logged
  • Invite consumption and access denials are stored for review
  • Admin actions are recorded in a dedicated log

Content safety

  • Rate limits and anti-spam controls on chat
  • Message reporting and moderation workflow
  • Attachment size and format limits
  • Suspicious redirect targets are refused after auth

Report a security issue

Please send reproduction steps and impact to security@kangopenbanking.com.

Data protection at a glance

Encryption in transit with modern TLS on every request.

Encryption at rest for the primary database and object storage.

Automated daily backups with point-in-time recovery on the primary database.

Regional hosting with edge delivery for public assets only.

Secrets stored in a managed vault, never in source code.

Least-privilege service accounts for backend and cron tasks.

How we handle personal data

We collect only what is required to run the workspace. Personal data (names, emails, phone numbers, mobile-money identifiers) is scoped to the workspace it was submitted in and to the roles that legitimately need it. We do not sell personal data and we do not use workspace content to train third-party models.

See the Privacy Policy for full details, retention periods, subprocessor list and how to exercise your rights.

Compliance context

Kang Workspace aligns with the Cameroonian cybersecurity framework (Law No. 2010/012), the electronic communications framework (Law No. 2010/013) and consumer protection under Law No. 2011/012. For financial workflows we follow CEMAC/BEAC regulations and ANTIC guidance. This page describes controls implemented today — it is not a third-party certification.

Shared responsibility

Kang Workspace is responsible for

  • Platform security, patching and infrastructure
  • Encryption, backups and access control primitives
  • Product-level audit logs and moderation tooling

Workspace owners are responsible for

  • Inviting the right people and setting permission templates
  • Reviewing access, audit logs and invite telemetry
  • Classifying and handling content added to the workspace

Responsible disclosure

We welcome coordinated disclosure from independent researchers. Please avoid data extraction, service disruption and testing against other customers' workspaces. Report to security@kangopenbanking.com and allow us reasonable time to remediate before public disclosure.