Security

Your data. Protected by default.

Kovee applies safeguards appropriate for a rental-management platform and clearly explains where your data may flow.

01

Infrastructure and location

The application, database, and operational services are hosted with selected cloud providers. Some services may process data in Canada, the United States, or other regions. Transfers are limited to service needs and governed by our agreements with providers.

02

Encryption and passwords

Communications with Kovee use HTTPS/TLS. Infrastructure providers apply encryption to their managed storage services. Kovee passwords are hashed with bcrypt and are not stored in plain text.

03

Authentication

Two-factor authentication is available to strengthen account protection. Sessions and access tokens are limited and managed server-side. We recommend using a unique password and enabling two-factor authentication.

04

Data access

Access to production environments and data is limited to people and services that need it to operate, support, or secure Kovee. Permissions are restricted according to responsibilities.

05

Ownership and control

You retain your rights to the data you add to Kovee. Export tools are available for several data sets and reports. You may also request access, correction, or deletion in accordance with our privacy policy and applicable legal obligations.

06

Backup and continuity

We use our infrastructure providers' backup and resilience mechanisms and maintain continuity and recovery procedures. Their scope may evolve with the service architecture.

07

Payments

Payments are processed by Stripe. Kovee does not store full card numbers on its servers. Stripe maintains its own security controls and certifications for payment processing.

08

Artificial intelligence

To answer a request, Kovee Agent may send AI providers the context required for that task. We limit that context to the requested work. Always review important answers: Kovee Agent assists your work but does not replace your judgment or legal, tax, or professional advice.

09

Incidents

We maintain an incident-management process. If an incident creates a real risk of significant harm, affected people and authorities are notified as required by applicable law.

10

Responsible disclosure

If you discover a potential vulnerability, email security@kovee.io with reproduction steps and observed impact. We will assess the report and coordinate the appropriate follow-up.

Key service providers

These providers may process data depending on the features you use. The list and regions may evolve with our services.

VendorPurposeRegion
RailwayAPI, database, and application servicesCanada / United States depending on service
CloudflareDocument storage, network, DNS, and email routingGlobal network
VercelMarketing-site hostingGlobal network
StripePayments and subscriptionsCanada / United States
Resend / SendGridTransactional emailUnited States
OpenRouter / GroqArtificial-intelligence servicesUnited States / model dependent
TavilyWeb search used by Kovee AgentUnited States
SingleKeyCredit and background checksCanada
PostHogConsent-based usage analyticsDepends on service configuration
ExpoTechnical services for the mobile applicationUnited States / global network
CrispCustomer support and messagingEuropean Union / global network

A question about security?

For a question or responsible vulnerability report, use our dedicated address.

security@kovee.io