Trust & security

Controls you can inspect, evidence you can point at.

Kiosk is built around the controls a security review asks about: least-privilege access to data, an append-only record of every change of state, and a documented process for handling disputes and data requests.

Access control

Every table enforces row-level access rules. Roles are stored separately from profiles so a user cannot grant themselves elevated access.

Audit trail

Order state changes, seller verification decisions and privacy requests are written to an append-only log no user can edit or delete.

Transaction evidence

Each order carries a reference, a full state history with timestamps and actors, fulfilment notes and any risk flags raised at purchase.

Account protection

Passwords are checked against known breach corpora, and changing a password requires the current one.

Risk screening

Orders are scored at creation against velocity, value, quantity and seller-history rules, and flagged for review.

Your data

Signed-in users can export everything Kiosk holds about them and register a deletion request from their account page.

Control register

Mapped to the SOC 2 Trust Services Criteria. SOC 2 is an audit of an organisation performed by an independent firm; this register records the technical controls implemented in the platform and the evidence available for each. It is not a certification.

CC6.1

Logical access control

Every data table enforces row-level security. Access is scoped to the signed-in user and their assigned role; roles are stored separately from profile data to prevent privilege escalation.

Evidence: Database policies on all application tables

Engineeringimplemented
CC6.2

Account provisioning

Accounts are created only through the authentication service. Every new account is provisioned with the least-privileged buyer role by default.

Evidence: Account creation trigger and role table

Engineeringimplemented
CC6.3

Privileged access

Administrative actions are verified on the server against the roles table. Hiding an interface element is never used as an access control.

Evidence: Server-side role checks in transaction functions

Engineeringimplemented
CC6.6

Credential protection

Passwords are checked against known-breach datasets, and changing a password requires the current password.

Evidence: Authentication configuration

Securityimplemented
CC7.2

Monitoring and audit trail

Security-relevant and privileged actions are written to an append-only audit log with actor, action, entity and timestamp.

Evidence: Audit log table, admin console

Securityimplemented
CC7.3

Incident evidence

Every order carries an immutable event history so incidents and complaints can be reconstructed.

Evidence: Order event trail

Operationsimplemented
CC8.1

Change and state control

Order state changes are validated server-side against a defined transition map. Invalid transitions are rejected.

Evidence: Transaction state machine

Engineeringimplemented
PI1.2

Input validation

All inputs to server operations are schema-validated before any database write.

Evidence: Validation schemas on server functions

Engineeringimplemented
A1.2

Backup and recovery

Managed database with automated backups and point-in-time recovery provided by the hosting platform.

Evidence: Platform backup configuration

Engineeringimplemented
C1.1

Data segregation

Buyers, sellers and administrators can read only the records they are party to; cross-tenant reads are blocked at the database.

Evidence: Row-level security policies

Engineeringimplemented
P4.2

Data subject requests

Signed-in users can request an export of their data or deletion of their account from within the application.

Evidence: Privacy request workflow

Operationsimplemented
CC9.2

Third-party risk

Movement of customer funds is delegated to a licensed payment partner. The platform records order state and never holds regulated funds itself.

Evidence: Payment partner assessment pending Qatar licensing review

Compliancein progress

Payment processing currently runs in a clearly labelled sandbox. Kiosk does not hold or move customer funds; that will be carried out through a licensed payment partner in each launch country once appointed.