Security & Privacy

Learn how KredPilot protects your data and maintains the highest security standards to keep your professional reputation safe.

Data Protection

Your data security is our top priority. We implement multiple layers of protection to ensure your information remains safe and confidential.

Encryption

Data in Transit

All data transmitted between your browser and our servers is encrypted using TLS 1.3 with 256-bit encryption. This ensures that your credentials, ratings, and personal information cannot be intercepted during transmission.

Data at Rest

All sensitive data stored in our databases is encrypted using AES-256 encryption. This includes passwords (which are also hashed with bcrypt), payment information, and personal details.

Authentication Security

Session Tokens

Secure, signed tokens with 15-minute expiration stored in httpOnly cookies

Token Rotation

Automatic refresh token rotation with reuse detection

Password Hashing

Bcrypt with salt rounds for irreversible password storage

HttpOnly Cookies

Tokens stored in secure, httpOnly cookies to prevent XSS attacks

Infrastructure Security

Database Security

PostgreSQL with row-level security policies, parameterized queries to prevent SQL injection, and automated backups with 30-day retention.

DDoS Protection

Rate limiting on API endpoints (1,000 req/hour for Pro users) and Cloudflare protection against distributed denial-of-service attacks.

Regular Updates

All dependencies and frameworks are kept up-to-date with security patches applied within 24 hours of disclosure.

Security Monitoring

Our systems are monitored 24/7 for suspicious activity. We log all authentication attempts, API requests, and administrative actions for audit purposes. Anomalies trigger immediate alerts to our security team.

Privacy Controls

You have complete control over your data and who can see your professional information. KredPilot provides granular privacy settings to match your comfort level.

Profile Visibility

Public Profile

DEFAULT

Your profile, ratings, and trust score are visible to everyone on the internet. This is recommended for maximum credibility.

Best for freelancers and consultants

Hide Email Address

FREE

Keep your email private on your public profile while remaining visible to potential clients through the platform.

Protect against spam and unsolicited contact

Search Engine Control

PRO

Control whether your profile appears in Google and other search engines. Your profile remains fully transparent on KredPilot, but you decide on external discoverability.

Manage public discoverability while maintaining transparency

Data You Control

Email Visibility

Choose whether your email is visible on your public profile

Location Display

Show or hide your city and country information

Rating Comments

Toggle visibility of written feedback on individual ratings

Project History

Control whether your project list is publicly visible

Your Rights

Access Your Data

Request a complete export of all your data at any time. We'll provide a JSON file with your profile, ratings, projects, and activity logs within 48 hours.

Correct Your Data

Update or correct any inaccurate information in your profile directly through your dashboard settings at any time.

Delete Your Account

Permanently delete your account and all associated data. This action is irreversible and removes all your ratings, projects, and profile information within 30 days.

Cookie Policy

We use essential cookies for authentication and security. We do not use tracking cookies or share data with third-party advertisers. Analytics are anonymized and used solely to improve platform performance.

Compliance

KredPilot adheres to international data protection regulations and industry best practices to ensure your information is handled responsibly.

Regulatory Compliance

GDPR

General Data Protection Regulation (EU)

  • Right to access and data portability
  • Right to erasure (right to be forgotten)
  • Data processing transparency
  • 72-hour breach notification

CCPA

California Consumer Privacy Act (US)

  • Disclosure of data collection practices
  • Right to opt-out of data sales
  • Non-discrimination for privacy rights
  • Consumer data access requests

PCI DSS

Payment Card Industry Data Security Standard

  • Stripe-managed payment processing
  • No card data stored on our servers
  • Tokenized payment methods only
  • Annual security assessments

SOC 2

Service Organization Control 2 (In Progress)

  • Third-party security audits
  • Security, availability, processing integrity
  • Confidentiality and privacy controls
  • Expected certification: Q2 2026

Data Handling Practices

Data Minimization

We only collect data that's absolutely necessary to provide our services. No unnecessary tracking, profiling, or behavioral analytics. Your professional reputation data is the focus—nothing more.

Purpose Limitation

Your data is used exclusively for the purposes you agreed to: managing your professional reputation, processing ratings, and providing platform features. We never sell or share your data with third parties for marketing.

Data Retention

Active accounts: Data retained indefinitely. Inactive accounts (no login for 2+ years): Automated notification before data archival. Deleted accounts: All personal data removed within 30 days, ratings anonymized for platform integrity.

Third-Party Processors

We work with trusted service providers who meet our security standards:

  • Vercel: Hosting and deployment (ISO 27001 certified)
  • Supabase: Database hosting (SOC 2 Type II compliant)
  • Stripe: Payment processing (PCI DSS Level 1)
  • Resend: Transactional emails (GDPR compliant)

Security Incident Response

In the unlikely event of a data breach:

< 1 hour

Internal detection and containment

< 24 hours

Affected user notification

< 72 hours

Regulatory authority notification

Contact Our Privacy Team

For privacy concerns, data access requests, or compliance questions, contact our Data Protection Officer at privacy@kredpilot.com. We respond to all inquiries within 48 hours.