Kaitier LLC
How we protect systems, data, credentials, and customer accounts.
Last updated July 13, 2026
Version: 1.0 · Effective date: July 13, 2026 · Owner: Joseph Omara, Founder & Managing Member
Review frequency: Annually, or upon significant changes to infrastructure or security controls.
Kaitier LLC ("Kaitier") is committed to protecting customer information, financial data, and business systems from unauthorized access, disclosure, modification, or destruction.
This Information Security Policy establishes the administrative, technical, and operational safeguards used to protect customer information and company assets.
This policy applies to all Kaitier employees, contractors, and administrators; cloud infrastructure; source code repositories; customer data; internal systems; third-party services used by Kaitier; and production and development environments.
Kaitier's security program is designed to ensure confidentiality of customer information; integrity of financial records; availability of systems and services; protection against unauthorized access; and compliance with applicable privacy and security laws.
The Founder and Managing Member is responsible for maintaining the company's information security program.
Responsibilities include reviewing security controls; managing access permissions; monitoring security events; coordinating incident response; maintaining security documentation; and performing periodic policy reviews.
Kaitier follows the principle of least privilege. Access is granted only to individuals requiring access to perform legitimate business functions.
Controls include unique user accounts; strong password requirements; multi-factor authentication (MFA) for administrative accounts whenever supported; immediate removal of access when no longer required; and role-based access controls as the application evolves. Administrative access is restricted to authorized personnel.
Customer authentication is required before accessing protected resources.
Administrative systems use MFA whenever available, including Google Workspace; source code repositories; cloud hosting; financial platforms; and banking services.
Passwords are never stored in plaintext.
Customer information is processed only for providing Kaitier services.
Customer data includes receipts; expense records; transaction metadata; uploaded documents; email-derived receipt information; and connected financial account metadata.
Access to customer information is restricted to authorized systems and personnel.
Kaitier protects customer information using modern encryption practices.
Data in transit: All production communications use HTTPS with TLS 1.2 or newer. OAuth authentication is used for supported third-party integrations.
Data at rest: Sensitive customer information is stored using encrypted storage provided by hosting providers where available. Passwords are securely hashed using industry-standard password hashing algorithms. Secrets and API credentials are stored separately from application code.
Kaitier uses trusted third-party providers including Google Workspace, OpenAI, Resend, Microsoft, Google, Plaid (Premium features), and cloud hosting providers.
Third-party integrations are evaluated before use. Access permissions requested from customers are limited to those required to deliver the service.
Kaitier follows secure software development practices including source code version control; incremental feature development; authentication on protected routes; security testing during development; dependency updates; and code reviews when practical.
Security issues identified during development are prioritized according to risk.
Kaitier actively monitors security advisories affecting software dependencies.
Security patches are applied as soon as reasonably practical based on severity. Critical vulnerabilities receive expedited remediation.
System logs may include authentication events; failed login attempts; administrative actions; API errors; and security-related events.
Logs are retained for operational troubleshooting and security investigations.
If a security incident is suspected, Kaitier will: (1) identify the incident; (2) contain the affected systems; (3) investigate the root cause; (4) remediate vulnerabilities; (5) restore affected services; (6) notify affected customers when required by applicable law.
Security incidents are documented and reviewed to improve future response.
Customer information is retained only as necessary to provide services or satisfy legal obligations.
Customers may delete receipts, uploaded files, and associated records through the application where supported. Backups are retained according to operational requirements.
Kaitier collects only information necessary to provide requested services. Customer information is never sold to third parties.
Information is shared only with customer-authorized integrations; to provide requested services; or when legally required.
Personnel with access to production systems are expected to maintain strong passwords; use MFA where available; protect company devices; report suspected security incidents immediately; and avoid sharing credentials.
Kaitier maintains backups and recovery procedures appropriate for business operations.
Critical services are monitored to reduce downtime. Recovery procedures are periodically reviewed.
This policy is reviewed at least annually or after significant changes to infrastructure, security controls, or regulatory requirements.
Security concerns, vulnerability disclosures, and security-related questions: security@kaitier.com
General support: support@kaitier.com · Privacy inquiries: privacy@kaitier.com
Approved by Joseph Omara, Founder & Managing Member, Kaitier LLC.
Effective date: July 13, 2026.
Questions? security@kaitier.com