Security
How we keep your information safe
Kinvault is designed to hold some of the most sensitive information in your (or your client's) life. That only works if you can trust how it is protected.
Security by design
- Hosted on UK-based Amazon Web Services (AWS) infrastructure
- We use strong encryption to protect your data
- Kinvault holds Cyber Essentials Plus certification
- We carry out regular independent penetration testing
- Multi-factor authentication and strict access controls to protect accounts
Where your data is stored
Kinvault runs on Amazon Web Services with data stored in UK datacentres. That means your data stays in the UK, and it sits on infrastructure operated by one of the major global cloud providers.
We add our own application-level controls on top of AWS, including how information is structured, protected and handed over.
Encryption
Kinvault uses AES-256-GCM encryption to protect data.
- AES (Advanced Encryption Standard) is a widely used encryption standard adopted around the world for protecting sensitive information
- 256-bit keys (AES-256) are used where a high level of cryptographic strength is required
- GCM (Galois/Counter Mode) is a mode of operation that provides both confidentiality and integrity, helping detect if encrypted data has been altered
In practical terms, this level of encryption means that even if someone were able to get hold of the stored data, they would not be able to read it without the correct keys.
Independent testing
The Kinvault platform is regularly penetration-tested, independently audited and assessed for vulnerabilities. This helps confirm that key security controls are working as intended.
Access and sign-in
Signing in uses multi-factor authentication as well as a password to confirm the person logging in is really you. This reduces the risk of someone accessing an account or system simply by guessing or stealing a password.
Safely stored and carefully handed over
When the time comes to hand over a vault, our bereavement team confirms identity and carries out detailed checks.
This is designed to balance security and privacy with the need for families and advisers to get the information they need.
- Kinvault does not automatically release information as soon as a death is reported
- A specialist bereavement team checks what has happened and who is asking for access
- Information is only handed over when those checks have been completed
Shared responsibility
No online service can remove every risk. Good security is always a partnership between the people who build the service and the people who use it.
Our role is to provide:
- Secure infrastructure and encryption
- Independently assessed cyber security controls
- Careful processes for verifying identity and handing over information
In return, we ask that you:
- Keep your sign-in details private
- Choose a strong, unique password
- Tell us or your provider promptly if you think your account has been compromised
Together, those things help make sure the information in your Kinvault is protected and only reaches the people you choose, at the time you intend.
If you have questions about security or privacy that are not covered here, you can contact the Kinvault team at support@kinvault.com.