Security & Trust Centre
- Overview
- Security Principles
- Infrastructure
- Encryption
- Authentication
- Access Control
- Tenant Isolation
- Audit Logging
- Mobile Security
- Data Protection
- Backups
- Monitoring
- Incident Response
- Secure Development
- Responsible Disclosure
1. Overview
Kraylo is designed for businesses that rely on accurate operational data, including inventory, stock, orders, drivers, vehicles, banking records, approvals and reporting. Security and trust are core to how the platform is designed and operated.
2. Security Principles
- Protect customer data by default.
- Limit access using role-based permissions.
- Separate company data in a multi-tenant environment.
- Log significant actions for accountability.
- Use secure cloud infrastructure and encrypted connections.
- Design operational workflows with review and approval controls.
3. Infrastructure Security
Kraylo is hosted on secure cloud infrastructure. Access to production systems should be restricted to authorised personnel and protected using strong authentication, least-privilege access and operational controls.
4. Encryption
Kraylo uses HTTPS/TLS to protect data transmitted between users, browsers, mobile devices and the platform. Passwords are not stored in plain text and are handled through secure authentication mechanisms.
5. Authentication and Session Security
Users must authenticate before accessing protected areas. Sessions should be managed securely and can be revoked or expire according to platform configuration. Customers are responsible for ensuring users protect their credentials.
6. Role-Based Access Control
Kraylo supports user roles such as company administrators, managers and drivers. Permissions should be configured to ensure users only access the records and actions necessary for their responsibilities.
7. Multi-Tenant Company Isolation
Kraylo is designed to separate customer organisation data using company-level scoping and database access controls. Users should only access data belonging to their authorised organisation unless platform administration access is expressly granted.
8. Audit Logging
Kraylo records significant operational actions such as approvals, rejections, banking reviews, record changes, permission changes and administrative actions. Audit logs support accountability, investigations and operational governance.
9. Mobile App Security
The Kraylo iOS app is designed for authorised users. Mobile data may be synchronised with the platform and may be temporarily available offline. Users should secure devices with passcodes or biometric protection and keep the operating system updated.
10. Data Protection
Kraylo's privacy and data processing commitments are described in the Privacy Policy and DPA. Customer Data is processed to provide the service and is not sold.
11. Backups and Recovery
Kraylo should maintain backup and recovery practices appropriate to the production environment. Before publishing this page, confirm the actual backup frequency, retention period, restoration testing and disaster recovery objectives.
12. Monitoring and Reliability
Kraylo may use monitoring, logging and diagnostics to detect errors, investigate incidents, improve performance and maintain reliability. Monitoring should be configured to minimise unnecessary personal data collection.
13. Incident Response
Kraylo maintains an incident response approach for identifying, assessing, containing and resolving security incidents. Where a personal data breach affects Customer Data, Kraylo will notify affected customers in accordance with the DPA and applicable law.
14. Secure Development
Kraylo should follow secure development practices including code review, dependency management, environment separation, secrets management, testing and security-focused changes for authentication, authorisation and database access.
15. Responsible Disclosure
If you believe you have discovered a security issue, contact Kraylo at support@kraylo.co.uk with details sufficient to reproduce and assess the issue. Do not access, modify, delete or disclose customer data, and do not disrupt the service.