TRUST
Security Policy
Kinelio protects account, memorial and family operations with layered application and infrastructure controls.
1. Current controls
- TLS for public web traffic.
- Authenticated owner and family actions with CSRF/session protections.
- Cloudflare Turnstile on selected human authentication and activation forms.
- Administrative access restricted separately at the server layer.
- Protected server-side secrets and production rollback checkpoints.
- Separation between Kinelio Core and the Issuer machine/API service.
2. Responsible disclosure
If you believe you found a security vulnerability, use the support/contact channel published by Kinelio and clearly identify the report as security-related. Include enough detail to reproduce the issue without sending unnecessary personal data.
3. Safe research boundary
Do not access other users' data, perform destructive testing, degrade availability, social-engineer users or staff, or exploit a vulnerability beyond what is necessary to demonstrate it. This policy does not create authorization where the law or service rules do not provide it.
4. Incident handling
Kinelio may investigate, contain, remediate and document security incidents and notify affected parties or authorities where required by applicable law.