Technology • Business • Innovation • ImpactCapability Statement
Trust Center

Security

The security practices currently used to protect KGG systems and the information entrusted to us.

Draft — subject to legal review. This text is editable by KGG administration and has not yet been finalized by legal counsel.

Access control

The admin area requires sign-in. Staff join by invitation only and receive role-based permissions; financial and sensitive records are limited to authorized roles and enforced by the database itself.

Encryption

Traffic to this website is encrypted in transit using HTTPS. Data is stored with our hosting provider's encryption at rest.

Secure hosting

The website and its data run on managed cloud infrastructure. Uploaded documents are kept in private storage and are shared only through short-lived, permission-checked links.

Backups

Data is backed up by our managed database provider.

Incident response

Suspected security issues are investigated and addressed promptly. Formal incident response procedures are being documented.

Vendor management

We use established service providers and review their security posture when selecting them.

Secure development

Public forms are validated on the server, and visitors cannot write directly to our records or storage.

Vulnerability management

Dependencies and configuration are reviewed for known issues. To report a potential vulnerability, please use the Contact page.

Certifications

KGG does not currently claim SOC 2, ISO 27001, CMMC, FedRAMP or other formal security certifications. Any certification will be listed here only after it has been verified.