1.Our commitment
Security is foundational to KPI360. Your data is isolated per company, encrypted, access-controlled, and never sold. We follow the principle of least privilege and design the platform so that one company can never see another’s data.
2.Encryption
- In transit: all traffic to and from the Service is encrypted using TLS (HTTPS).
- At rest: data stored in our managed database and object storage is encrypted at rest by our infrastructure providers.
3.Tenant isolation & access control
Each client company operates in its own logical workspace. Data is partitioned per tenant, and every request runs within a single tenant’s context, so users only ever access their own company’s data. Platform-level administration is restricted to the KPI360 owner and is not visible to client users. Within a company, access is role-based — owners and managers see only the locations and features they are granted.
4.Authentication
Access requires authentication. We support single sign-on with Google and email-based access controls, and we scope each user to their permitted locations and features. Credentials and secrets are stored server-side and never exposed to the browser.
5.Infrastructure & hosting
KPI360 runs on established U.S. cloud infrastructure with reputable providers, using managed, continuously-patched services rather than self-managed servers. Application secrets are stored as encrypted environment variables and are not committed to source control.
6.Data ownership & portability
You own your data. We process it only to provide the Service and per your instructions (see our DPA). You can request an export of your Customer Data, and on termination we delete or de-identify it within a reasonable period.
7.Availability & durability
Your data is stored in encrypted, managed cloud services — object storage and a managed PostgreSQL database — operated by established U.S. infrastructure providers with storage-layer redundancy. The platform runs on serverless infrastructure with cached snapshots for fast, reliable reads, and your source systems (your POS and spreadsheets) remain an independent copy of record. You can export your data at any time.
8.Subprocessors
We use a small set of vetted subprocessors to deliver the Service. Each is bound by contractual data-protection obligations.
| Subprocessor | Purpose | Region |
|---|---|---|
| Vercel | Application hosting & delivery | United States |
| Neon | Managed PostgreSQL database | United States |
| Stripe | Payment processing | United States |
| Anthropic | AI insights (business API; no model training on submitted data) | United States |
| Authentication (sign-in) & optional Sheets integration | United States |
We will provide notice of material subprocessor changes as described in the DPA.
9.Vulnerability & incident response
We monitor the platform, apply security updates to our dependencies, and maintain an incident-response process. In the event of a personal-data breach affecting your data, we will notify affected customers without undue delay as required by law and our DPA, and cooperate on remediation.
10.Compliance posture
KPI360 is built to align with widely recognized security principles and to support customers’ obligations under privacy laws including the GDPR, CCPA/CPRA, and applicable U.S. state laws. A Data Processing Addendum is available for customers who require one. Formal third-party attestations (e.g., SOC 2) are on our roadmap; we do not currently claim any certification we have not completed.
11.Responsible disclosure
If you believe you’ve found a security vulnerability, please report it to security@kpi360.ai. We appreciate good-faith research and will work with you to validate and address valid reports.
12.Contact
Security questions: security@kpi360.ai. KPI360, New York, NY.