Security Policy

Zero-trust architecture, cryptographic safeguards, and how to report a vulnerability to us.

Effective
September 4, 2026
Entity
Antigravity
Jurisdiction
India
Applies to
kafei.in
TLS 1.3 & AES-256

End-to-end encryption in transit and at rest across all database clusters.

Multi-Tenant Isolation

Logical database partitioning preventing cross-account data leakage.

Certified hosting

Runs on cloud providers holding SOC 2 Type II and ISO 27001 certification.

1. Information Security Architecture

Security is built into the core of the Kafei architecture. As an enterprise restaurant operating system managing live point-of-sale terminals, kitchen displays, payment transactions, and confidential business metrics, we implement a Zero-Trust security model and defense-in-depth engineering principles.

2. Encryption Standards & Data Protection

2.1 Encryption in Transit

  • All communications between clients (browsers, tablets, POS terminals, mobile devices) and Kafei servers are encrypted using Transport Layer Security (TLS 1.3 / HTTPS).
  • HTTP Strict Transport Security (HSTS) is strictly enforced with preloading enabled.

2.2 Encryption at Rest

  • Sensitive user data, database volumes, and automated backups are encrypted at rest using AES-256.
  • Database passwords and authentication secrets are hashed using strong, salted algorithms (Argon2 / bcrypt).

3. Google OAuth 2.0 & Token Security

  • Minimal Scopes: We request only essential identity scopes (openid, email, profile).
  • No long-lived Google tokens: We do not request offline access and we do not store Google refresh tokens. The short-lived access token returned at sign-in is used once, server-side, to read your email and profile, and is never logged or persisted.
  • Revocation: Disconnecting Google in Kafei, or revoking access from your Google account, takes effect immediately. Account deletion purges the stored identity link. See the Privacy Policy.

4. Infrastructure & Cloud Security

  • Enterprise cloud hosting: Infrastructure runs on providers that hold ISO 27001, SOC 2 Type II, and PCI-DSS Level 1 certifications for their own facilities. Kafei does not itself hold these certifications and does not claim to.
  • DDoS Mitigation & WAF: Real-time protection against distributed denial-of-service (DDoS) attacks via Cloudflare edge routing.
  • Automated Backups: Point-in-time database snapshots are taken daily, encrypted, and replicated across geographically redundant storage regions.

5. Vulnerability Management & Responsible Disclosure

We welcome security researchers to report potential vulnerabilities. Please email reports to security@kafei.in.

  • Acknowledgment: Within 24 hours.
  • Triage & Assessment: Within 72 hours.
  • Resolution: Remediations prioritized by CVSS severity score.

Questions about this policy?

Write to us for data subject requests, deletion requests, security reports, or compliance reviews. We respond within 5 business days.

Antigravity, Kolkata, West Bengal, India