How we protect the data of operators, buyers and residents. Last updated 22 June 2026.
Customer and product data is stored in Australia, on cloud infrastructure hosted in the Sydney region. Your community's data stays onshore.
All traffic to and from kinHome is encrypted in transit using TLS. Data is encrypted at rest in our database and file storage.
kinHome is multi-tenant, and every operator's data is strictly isolated. Access is enforced at the database level using row-level security, so one operator can never reach another's data, even through the application. Within an operator's account, what each person can see is governed by the roles and permissions you control.
Access to the application requires authentication. Operators manage their own users and the level of access each one has. Internally, access to production systems is limited to authorised personnel on a need-to-know basis.
Documents such as contracts and disclosure materials are held in private storage. They are never publicly accessible. Access is granted through short-lived, signed links to the people entitled to see them, governed by the same permission rules as the rest of the platform. When you upload a document, the file moves directly to secure storage rather than passing through and lingering on our servers.
We build security into how we work: code review, dependency management, and least-privilege access to systems. Features are designed so that data is protected by default rather than as an afterthought.
Data is backed up so that it can be recovered, and we design the platform to be resilient and to recover from failures.
We monitor our systems and maintain a process for responding to security incidents. If an incident affected your data, we would notify you in line with our obligations, including the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth).
We use a small number of trusted providers, such as cloud hosting and email delivery, to run kinHome. They operate under contract, and we hold them to security standards consistent with our own. Our Privacy Policy explains how information is handled.
Security is shared. Operators should use strong, unique passwords, manage user access carefully, remove users when they leave, and collect only the information they need. We provide the controls; how you use them matters.
If you believe you have found a security issue, please contact us at hello@kinhome.io. We welcome responsible disclosure and will work with you to resolve genuine issues promptly.
We're happy to take your security or IT team through how the platform works.