Security at Kang Workspace
The controls below ship with every workspace today. This page is maintained by the Kang team and does not represent a third-party certification.
Access controls
- — Workspace-scoped permissions on every read and write
- — Role-based team management (owner, admin, member)
- — Per-workspace permission templates for common team shapes
- — Sign-in via password or Google, with optional route protection
Data protection
- — HTTPS with modern TLS for all traffic
- — Row-level security enforced at the database
- — Signed URLs for private storage assets
- — Least-privilege service accounts for backend operations
Audit & traceability
- — Every HR approval records actor, timestamp and outcome
- — Chat message edits and deletes are logged
- — Invite consumption and access denials are stored for review
- — Admin actions are recorded in a dedicated log
Content safety
- — Rate limits and anti-spam controls on chat
- — Message reporting and moderation workflow
- — Attachment size and format limits
- — Suspicious redirect targets are refused after auth
Report a security issue
Please send reproduction steps and impact to security@kangopenbanking.com.
Data protection at a glance
Encryption in transit with modern TLS on every request.
Encryption at rest for the primary database and object storage.
Automated daily backups with point-in-time recovery on the primary database.
Regional hosting with edge delivery for public assets only.
Secrets stored in a managed vault, never in source code.
Least-privilege service accounts for backend and cron tasks.
How we handle personal data
We collect only what is required to run the workspace. Personal data (names, emails, phone numbers, mobile-money identifiers) is scoped to the workspace it was submitted in and to the roles that legitimately need it. We do not sell personal data and we do not use workspace content to train third-party models.
See the Privacy Policy for full details, retention periods, subprocessor list and how to exercise your rights.
Compliance context
Kang Workspace aligns with the Cameroonian cybersecurity framework (Law No. 2010/012), the electronic communications framework (Law No. 2010/013) and consumer protection under Law No. 2011/012. For financial workflows we follow CEMAC/BEAC regulations and ANTIC guidance. This page describes controls implemented today — it is not a third-party certification.
Responsible disclosure
We welcome coordinated disclosure from independent researchers. Please avoid data extraction, service disruption and testing against other customers' workspaces. Report to security@kangopenbanking.com and allow us reasonable time to remediate before public disclosure.
