Compliance roadmap
KMFCRE is actively preparing for formal SOC 2 Type II and ISO/IEC 27001 attestations. We are aligning our policies, access controls, monitoring, and vendor management program to those frameworks today, and will publish audit reports here once completed.
Trust Services Criteria — Security
Information Security Management System
Enterprise customers evaluating KMFCRE can request our current security questionnaire and roadmap by emailing info@kmfcre.com.
How we protect your data
The controls below are enabled on the platform today. They're the foundation the formal SOC 2 and ISO 27001 programs are being built on.
Encryption in transit
All traffic to and from the platform is served over HTTPS/TLS. Custom domains are provisioned with managed certificates.
Encryption at rest
Customer data is stored in managed Postgres with encryption at rest handled by the underlying cloud provider.
Row-level access control
Every table enforces row-level security policies so users can only read or modify data they're authorized to see.
Authentication & MFA
Email/password and Google sign-in with support for multi-factor authentication and session timeout re-authentication.
Managed infrastructure
Hosted on modern cloud infrastructure with automated backups, isolated environments for development and production, and least-privilege service credentials.
Audit trails
Policy acknowledgements, disclaimer acceptances, tool usage, and administrative actions are logged with timestamp, IP, and user agent.
Monitoring & alerting
Application errors, authentication anomalies, and edge-function failures are monitored and surfaced to the engineering team.
Change management
Application changes flow through code review, automated typecheck, and preview environments before reaching production.
U.S. data residency
The platform operates from the United States and is intended for U.S. customers. Data is processed in the U.S.
Access control
Administrative access to production systems is restricted to a small number of engineering staff and is protected by multi-factor authentication. Access is granted on a least-privilege basis and reviewed periodically.
Application user roles are stored in a dedicated table (never on the user profile) and enforced by security-definer database functions to prevent privilege-escalation patterns.
Data handling & retention
We retain customer data for as long as the account is active and as required to provide the service, comply with legal obligations, resolve disputes, and enforce agreements. On account closure or deletion request, data is deleted or de-identified on a reasonable schedule, subject to legal retention requirements.
See our Privacy Policy for full details on collection, use, and user rights.
Subprocessors
We rely on established subprocessors for cloud hosting and database, payment processing, email and SMS delivery, mapping and property data, and AI features. Each subprocessor is engaged under a written agreement that restricts their use of customer information to providing services on our behalf.
A current subprocessor list is available on request from info@kmfcre.com.
Incident response
We maintain an incident response process covering detection, containment, notification, and post-incident review. In the event of a confirmed incident affecting customer data, we will notify affected customers without undue delay and in accordance with applicable law.
To report a suspected security issue or vulnerability, email info@kmfcre.com with details and reproduction steps. Please do not publicly disclose issues before we have had a reasonable opportunity to investigate and remediate.
Payments & PCI
Subscription and usage-based charges are processed by Stripe. Full payment-card details are collected and handled by Stripe under their PCI DSS Level 1 attestation and are never stored on KMFCRE servers.
Shared responsibility
Security is a partnership. KMFCRE is responsible for the platform, infrastructure, and the controls described on this page. Customers are responsible for using strong unique passwords, enabling MFA, managing team-member access, protecting API keys stored in their account, and complying with laws that apply to how they contact consumers (TCPA, CAN-SPAM, state privacy laws).
Have a security question?
Vendor reviews, security questionnaires, subprocessor lists, DPA requests, or to report a suspected vulnerability — we'll get back to you.