Security
How Kiko protects payroll, salary and identity data, and how to report something that looks wrong.
Last updated 1 September 2026
Kiko is a demonstration product. This document is written as a realistic sample and is not a binding agreement. Do not rely on it as legal advice.
1. Encryption
All traffic runs over TLS. Data at rest is encrypted with keys we rotate on a schedule. Bank accounts, permanent account numbers and salary figures carry an additional layer of field level encryption.
2. Access control
Access is role based, down to the field. A manager can approve leave for their team without ever seeing a salary. Compensation visibility is granted explicitly, never by default.
Single sign on through SAML and OpenID Connect is supported, along with multi factor authentication.
3. Separation of duties
Payroll enforces maker and checker separation. The person who runs a payroll cycle cannot be the person who approves it. Once approved, a run is immutable and corrections flow through the next cycle as arrears.
4. Audit trail
Every create, update and delete on a compensation, attendance, leave or payroll record writes an immutable audit event capturing the actor, the timestamp, the value before, the value after and the stated reason.
Attendance and payroll period locks are enforced on the server. Unlocking a locked period is itself an audited event.
5. Infrastructure
The platform runs on hardened cloud infrastructure with network isolation between environments. Production access requires named approval and is logged.
Backups are taken continuously and restore procedures are tested.
6. Reporting a vulnerability
Send findings to security@kiko.co. We acknowledge within one business day and will keep you updated until the issue is closed. We do not pursue legal action against researchers acting in good faith.
Still have a question?
Bring it to the demo and we will answer it on the call, or write to legal@kiko.co.
Book a demo