Skip to main content
Security & Privacy

Data Security Practices

Learn how Kawaa protects your data.

Infrastructure Security

  • Encryption in transit - All API calls use TLS 1.2 or later
  • Encryption at rest - Data encrypted with AES-256
  • AWS hosting - Enterprise-grade infrastructure

Access Control

  • Role-based access control (RBAC)
  • Two-factor authentication (2FA)
  • Hardware security key support (FIDO2) - coming soon
  • Audit log of account, security and billing actions (Enterprise plan)

Data Handling

  • Verification results are encrypted at rest and keyed by a one-way hash of the address
  • Results are retained for your plan's retention period (7-365 days), then deleted
  • Kawaa never reads your mailboxes; it only processes the addresses you submit

Security Reporting

Found a vulnerability? Report it to security@kawaa.com. We acknowledge every report.

Was this article helpful?

Saved on this device only. To reach us, email support@kawaa.com.

Still need help?

Can't find what you're looking for? Our support team is here to assist you.

Contact Support