Skip to main content

Trust

Security & Trust

A plain description of the measures protecting this website and the information you choose to send us.

Interim version

What we do not claim

No website is ever completely secure, and we will not tell you otherwise. We hold no security certification. We are not SOC 2 certified, not ISO certified and not approved by any regulator, and we do not display badges we have not earned. What follows is a factual description of measures actually in place.

In transit and at rest

  • The whole site is served over HTTPS, and browsers are instructed to refuse an unencrypted connection to it.
  • Your submissions travel directly to our managed database over an encrypted connection.
  • The database is encrypted at rest by the platform that operates it.

Who can read what you send

  • Registration and privacy-request records cannot be read from the public internet: the site can write a record but can never read one back.
  • Only authorised administrators, verified against the database itself, can read submissions. The role is decided on the server from a verified email address and can never be granted from the browser.
  • Administrators sign in without a password, using a single-use link sent to a verified address. No password for this site is ever created, stored or emailed.

On the page

  • A Content Security Policy restricts what the page may load or connect to.
  • The site refuses to be embedded in another site's frame, blocking clickjacking.
  • Browser features we do not need — camera, microphone, location, payment, sensors, ad-topic profiling — are switched off at the page level.
  • Everything you type is checked in the browser and again by the database before it is stored.
  • A hidden trap field and a short delay between attempts limit automated submissions.

What we deliberately avoid

  • No analytics, advertising, social or personalisation scripts.
  • No third-party video players, chat widgets or trackers.
  • No personal information in web addresses, in logs, or in notification emails.
  • No sensitive categories of information are requested anywhere on this site.

If something goes wrong

If you believe you have found a security problem, write to info@kaysoma.com with enough detail to reproduce it and give us a reasonable opportunity to fix it before disclosing it. We will not pursue anyone who reports in good faith and does not access or alter other people's information.

If an incident affects personal information, we will assess it and notify the people and authorities that the applicable law requires us to notify, within the deadlines it sets.

Retention and deletion

Enquiry records are kept for up to 24 months after our latest interaction unless the law requires longer. You can ask us to delete your information at any time through the data rights page; copies inside routine platform backups age out with those backups.