KinBridge handles sensitive data: health metrics, personal conversations with seniors, voice recordings, and end-of-life content. Security is foundational, not an afterthought. Here is what we do and how to report issues.

🔐

AES-256 Encryption

All data at rest

🔒

TLS 1.3

All data in transit

🧱

Isolated Biometrics

Voice prints in separate storage

📋

Audit Logs

All PHI access logged

🔑

RBAC

Role-based access controls

Auto Session Expiry

Inactivity timeout

Encryption

Data at Rest

Data in Transit

Access Control

Infrastructure Security

Biometric Data Special Protections

Voice prints used for Last Words voice cloning are subject to additional security controls:

Secure Development Lifecycle

Security Assessments

Responsible Disclosure

🔍 Found a Security Issue?

We appreciate responsible security research. If you've found a vulnerability, please report it to us before public disclosure so we can fix it first.

Email: security@kinbridge.app
Subject: [SECURITY] Brief description

Include: description of the issue, steps to reproduce, potential impact, and your contact information.

We commit to: acknowledge within 48 hours, provide status updates, fix critical issues within 14 days, and credit researchers in release notes (if desired).

Please do not: access or modify user data beyond what is needed to demonstrate the vulnerability, perform denial-of-service attacks, or disclose publicly before we confirm the fix.

Incident Response

Our incident response process:

Contact

Security issues: security@kinbridge.app
Compliance / BAA: enterprise@kinbridge.app
Privacy / DPO: dpo@kinbridge.app