Knodor · Effective 4 August 2026

Security Policy

How Knodor approaches application security, access control, and vulnerability reports.

Our approach

Knodor uses role-based access control, encrypted transit (HTTPS), session controls, and least-privilege practices across web and APIs. Effective date: 4 August 2026.

Your responsibilities

Protect your login credentials and devices, use strong passwords or passkeys where available, and report suspicious gate or account activity to your society managers promptly.

Report a vulnerability

If you discover a security issue, email support@knodor.com with subject “Security report”. Please include steps to reproduce and avoid public disclosure until we have had a reasonable time to investigate and fix.

Incidents

If a personal-data breach affecting you occurs, we will notify affected parties and regulators as required by applicable law.

Contact

Questions about this policy can be sent to support@knodor.com, or call +254 101 575757. Postal / registered address: Knodor, Nairobi, Kenya. Website: https://knodor.com.

This page is provided for transparency and product compliance. It is not formal legal advice. For society-specific rules, also follow your estate’s house rules.