Security that enables your operations

Security and privacy are not afterthoughts. They are what makes remote work, branch operations, cloud access, and global collaboration possible without abandoning accountability.

Cloud security concept with tablet showing global data protection

How Kraal Code protects your organisation

Every design decision in Kraal Code starts from a security question: who can see this, who can do this, and how is it recorded? The answers shape every module, every workflow, and every permission.

These are verified controls from the product's security architecture — not marketing promises.

Verified Security Controls

Tenant Isolation

Every organisation's data is isolated at the database level using row-level tenant isolation. The tenant ID comes exclusively from the server-side session — never from request parameters. Cross-tenant access returns HTTP 404 to prevent enumeration.

Role-Based Access Control

Unlimited roles with granular permissions, branch restrictions, and approval limits. Control who can create, approve, view, and export every type of record. Segregation of duties enforced by design.

Immutable Audit Trail

Every action — create, read, update, delete, approval, login, logout, role change — is recorded in an INSERT-only log. No one can alter or delete audit records. 7-year retention. External auditor read-only role available.

Encryption

TLS 1.3 for all traffic in transit. AES-256 encryption at rest for sensitive data: salary information, national IDs, bank account numbers, biometric identifiers. Bcrypt (cost ≥ 12) for passwords. Database backups encrypted.

Multi-Factor Authentication

TOTP-based two-factor authentication (NIST SP 800-63B AAL2). Biometric login support. Account lockout after 5 failed attempts. Session invalidation within 5 seconds of account disable.

OWASP Top 10 (2021) Mapped

Security architecture is designed against all ten OWASP Top 10 categories: broken access control, cryptographic failures, injection, insecure design, security misconfiguration, vulnerable components, authentication failures, software integrity, logging, and SSRF.

Rate Limiting

Token bucket algorithm, configurable per tenant, per user, and per subscription plan. HTTP 429 with Retry-After header when limits are exceeded.

Security Headers

Content-Security-Policy with per-request nonce. X-Content-Type-Options: nosniff. X-Frame-Options: DENY. Referrer-Policy: strict-origin-when-cross-origin. Permissions-Policy restricting camera, microphone, and geolocation.

Data Protection

Uganda PDPA 2019

Kraal Code is designed with controls informed by the Uganda Data Protection and Privacy Act 2019. The platform operates as data processor; the tenant is data controller.

Data Retention

Configurable retention periods per data category. Subject access export within 72 hours. Tenant offboarding: archive within 30 days, purge after 90 days, audit logs retained for 7 years.

Sub-Processor Register

Maintained and available on request. Consent capture for sensitive HR data. No cross-border transfers without documented legal basis.

Have security questions?

We take security seriously and are happy to discuss our controls with your IT team, security reviewers, or procurement panel.

Contact Our Team →