Security & Privacy

How Kit stores and protects your data

Core account data is stored on Hetzner in Nuremberg, Germany. This page lists the access controls, encryption, providers, and work still planned.

EU-Hosted (Germany)
Encrypted at Rest & In Transit Cloudflare Protected CI Security Scanning

Privacy & GDPR

Data Residency

Core account data is stored in Nuremberg, Germany. Our DPA describes sub-processors and the safeguards for any international transfers.

GDPR support

You get a Data Processing Agreement, account exports, anonymisation, consent records, and tools for responding to data subject requests.

Data Processing Agreement

Our DPA covers all GDPR Article 28 mandatory clauses, including sub-processor management, breach notification, audit rights, and international transfer safeguards.

View our DPA

Consent Management

Set candidate data retention periods, track consent, and manage expiry and renewal with an audit trail.

Compliance

GDPR

  • Data Processing Agreement available
  • Data subject rights supported (access, rectification, erasure, restriction, portability, objection)
  • Data export and anonymisation tools
  • Consent management with audit trail
  • EU-resident infrastructure
  • Also covers UK GDPR and Swiss FADP

ePrivacy

  • Microsoft Clarity records page use to show where people get stuck
  • Pages whose URL carries a token, sign-in link, or search text are never recorded
  • Clarity advertising storage stays off
  • One-click email unsubscribe (RFC 8058)

CCPA

  • No sale or sharing of personal information
  • Data deletion on request
  • Right to know what data is collected
  • Non-discrimination for privacy rights

Infrastructure

Hosting

The application and database run on Hetzner in Nuremberg, Germany. Core account data is stored in the EU. Other providers are listed below.

Data Residency

The database is not exposed to the public internet. Core account records and encrypted backups are stored in the EU.

Email Infrastructure

We run our own mail server in the EU for candidate emails and notifications. Delivery also involves the recipient's email provider.

Edge Security

Cloudflare handles edge traffic with DDoS protection, a web application firewall, and TLS. Its processing locations and transfer terms are listed in our DPA.

Encryption

In Transit

All connections are encrypted using TLS 1.2 or higher. HSTS is enforced. API endpoints require HTTPS.

At Rest

Sensitive personal fields use application-level encryption. Backups are encrypted before storage.

Payment Data

Stripe processes payments. Kit does not store full card numbers.

Application Security

Automated Security Scanning

CI checks include Brakeman for Rails security issues, bundler-audit for Ruby dependencies, and importmap audit for JavaScript dependencies.

Framework Protections

Rails provides protections against CSRF, XSS, and SQL injection. Kit also enforces Content Security Policy headers.

Code Review

Changes go through pull request review. RuboCop and ERB Lint check the code automatically.

Dependency Management

Dependency alerts identify known vulnerabilities. We update affected framework and library versions.

Access Control

Authentication

Passwords are hashed. Optional two-factor authentication adds a second sign-in check. Sessions use secure, HTTP-only cookies.

Team Permissions

Set an account role and a module access level for each teammate. Restrict individual job postings, security reports, or review cycles to named people. Each grant records its author and date. Delegated invitation rights cannot exceed the inviter's own access.

API Security

API tokens are scoped to the modules their owner can access and stored only as a hash. Rate limits apply to all API endpoints. Tokens can be rotated.

Internal Access

Engineering access uses individual credentials and the permissions needed for each person's work.

Sub-processors

These providers process data for Kit.

Provider Purpose Location
Hetzner Online GmbH Infrastructure, compute, storage Nuremberg, Germany
Cloudflare, Inc. CDN, DNS, DDoS protection Global (DPF + SCCs)
Stripe, Inc. Payment processing United States (DPF + SCCs)
Functional Software, Inc. (Sentry) Error tracking (PII scrubbed before transmission) United States (DPF + SCCs)
Axiom, Inc. Application logs (personal data scrubbed before shipping) EU (AWS Frankfurt)
Google LLC (Gemini API) Default AI model on Kit's included key, including spam screening of each new security report Per Google's Gemini API terms
TypeSafe AI, Inc. Prompt-injection scan and classification of security reports United States (SCCs)
Microsoft Corporation (Clarity) Usage analytics and session replay (30-day playback) Per Microsoft's Clarity terms

Vulnerability Disclosure

Our disclosure program has a submission form, triage process, and published policy. The policy lists our acknowledgment and resolution targets.

Our security.txt is published at security.startupkit.app/.well-known/security.txt

Uptime & Status

Check current availability, uptime history, and incident reports.

View status page

Questions?

For security questions, email us:

[email protected]

Last updated: September 25, 2026

Try Kit for 30 days

30 days free with core account data stored in the EU. Card required; cancel anytime.