How Kit stores and protects your data
Core account data is stored on Hetzner in Nuremberg, Germany. This page lists the access controls, encryption, providers, and work still planned.
Privacy & GDPR
Data Residency
Core account data is stored in Nuremberg, Germany. Our DPA describes sub-processors and the safeguards for any international transfers.
GDPR support
You get a Data Processing Agreement, account exports, anonymisation, consent records, and tools for responding to data subject requests.
Data Processing Agreement
Our DPA covers all GDPR Article 28 mandatory clauses, including sub-processor management, breach notification, audit rights, and international transfer safeguards.
View our DPAConsent Management
Set candidate data retention periods, track consent, and manage expiry and renewal with an audit trail.
Compliance
GDPR
- Data Processing Agreement available
- Data subject rights supported (access, rectification, erasure, restriction, portability, objection)
- Data export and anonymisation tools
- Consent management with audit trail
- EU-resident infrastructure
- Also covers UK GDPR and Swiss FADP
ePrivacy
- Microsoft Clarity records page use to show where people get stuck
- Pages whose URL carries a token, sign-in link, or search text are never recorded
- Clarity advertising storage stays off
- One-click email unsubscribe (RFC 8058)
CCPA
- No sale or sharing of personal information
- Data deletion on request
- Right to know what data is collected
- Non-discrimination for privacy rights
Infrastructure
Hosting
The application and database run on Hetzner in Nuremberg, Germany. Core account data is stored in the EU. Other providers are listed below.
Data Residency
The database is not exposed to the public internet. Core account records and encrypted backups are stored in the EU.
Email Infrastructure
We run our own mail server in the EU for candidate emails and notifications. Delivery also involves the recipient's email provider.
Edge Security
Cloudflare handles edge traffic with DDoS protection, a web application firewall, and TLS. Its processing locations and transfer terms are listed in our DPA.
Encryption
In Transit
All connections are encrypted using TLS 1.2 or higher. HSTS is enforced. API endpoints require HTTPS.
At Rest
Sensitive personal fields use application-level encryption. Backups are encrypted before storage.
Payment Data
Stripe processes payments. Kit does not store full card numbers.
Application Security
Automated Security Scanning
CI checks include Brakeman for Rails security issues, bundler-audit for Ruby dependencies, and importmap audit for JavaScript dependencies.
Framework Protections
Rails provides protections against CSRF, XSS, and SQL injection. Kit also enforces Content Security Policy headers.
Code Review
Changes go through pull request review. RuboCop and ERB Lint check the code automatically.
Dependency Management
Dependency alerts identify known vulnerabilities. We update affected framework and library versions.
Access Control
Authentication
Passwords are hashed. Optional two-factor authentication adds a second sign-in check. Sessions use secure, HTTP-only cookies.
Team Permissions
Set an account role and a module access level for each teammate. Restrict individual job postings, security reports, or review cycles to named people. Each grant records its author and date. Delegated invitation rights cannot exceed the inviter's own access.
API Security
API tokens are scoped to the modules their owner can access and stored only as a hash. Rate limits apply to all API endpoints. Tokens can be rotated.
Internal Access
Engineering access uses individual credentials and the permissions needed for each person's work.
Sub-processors
These providers process data for Kit.
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Infrastructure, compute, storage | Nuremberg, Germany |
| Cloudflare, Inc. | CDN, DNS, DDoS protection | Global (DPF + SCCs) |
| Stripe, Inc. | Payment processing | United States (DPF + SCCs) |
| Functional Software, Inc. (Sentry) | Error tracking (PII scrubbed before transmission) | United States (DPF + SCCs) |
| Axiom, Inc. | Application logs (personal data scrubbed before shipping) | EU (AWS Frankfurt) |
| Google LLC (Gemini API) | Default AI model on Kit's included key, including spam screening of each new security report | Per Google's Gemini API terms |
| TypeSafe AI, Inc. | Prompt-injection scan and classification of security reports | United States (SCCs) |
| Microsoft Corporation (Clarity) | Usage analytics and session replay (30-day playback) | Per Microsoft's Clarity terms |
Vulnerability Disclosure
Our disclosure program has a submission form, triage process, and published policy. The policy lists our acknowledgment and resolution targets.
Our security.txt is published at security.startupkit.app/.well-known/security.txt
Try Kit for 30 days
30 days free with core account data stored in the EU. Card required; cancel anytime.