Last updated June 2026

Security at Kolvera

Protecting your data is foundational to how we build Kolvera. This page outlines the security measures we have in place across authentication, encryption, infrastructure, and application design.

TL;DR

Bcrypt password hashing. TOTP two-factor authentication. Encryption at rest with integrity verification. Rate limiting on every endpoint. CSRF protection on all forms. Tenant-isolated multi-tenancy with user-level data scoping. Automated threat detection with IP auto-banning. Dedicated background worker architecture. Stripe handles all payments. All connections over HTTPS with HSTS. Continuous static analysis security scanning. Frontend and backend error monitoring with automatic alerting.

Authentication & Access Control

Data Isolation

Encryption

API & Rate Limiting

Threat Detection

Payment Security

Application Security

Document Signing Security

Email Security

SMS Security

Infrastructure

Third-Party Integrations

Responsible Disclosure

If you discover a security vulnerability, please contact us at security@kolvera.io. We take all reports seriously and will respond within 48 hours.

Kolvera is built and maintained in Australia. We are committed to protecting your data and continuously improving our security posture.

Ready to try it?

50 credits, no card required. See what secure, AU-first recruitment BD looks like.

Start Free Trial