KKitewise

Security and trust

Kitewise connects to the accounts your business depends on. Here's how we keep them, and your customers' data, safe.

A person approves every action

Posts, replies, ad campaigns and budget changes wait in Approvals until a workspace owner or admin approves them. Approved ad campaigns are created paused, and all campaigns are held to the workspace's daily spending limit. An automatic reply rule only runs if an admin turns it on, for the channels and kinds of messages they choose.

Every workspace is separate

Each business's data belongs to its own workspace, and access is checked on every request, including for agency staff working in client workspaces. Roles decide who can change settings and who can approve.

Encrypted connection keys

The access tokens and keys for your connected accounts (Facebook, Google, Slack, Stripe and others) are encrypted at rest with AES-256-GCM. They're decrypted only at the moment Kitewise needs them to act for you.

Sign-in without passwords

You sign in with a one-time code sent to your email. Codes expire after 10 minutes, work once, and lock after five wrong tries, and the number of codes per email is limited. Sessions are kept in a secure, HTTP-only cookie.

Signature-checked webhooks

Messages that arrive from Stripe, Meta, WhatsApp, Slack and the other chat apps are checked for a valid signature or secret before anything is processed.

Protection against unsafe links

When Kitewise fetches a web address you give it (a product feed, your website, a link in a reply), it only connects to public internet addresses over http or https, with limits on redirects, size and time. It can't be pointed at our own internal network.

Payments stay with Stripe

Payments on landing pages go through Stripe Checkout into the business's own Stripe account. Card details never reach us, prices are set in the app rather than read from the page, and only Stripe's confirmation marks a payment as paid.

An audit log

Approvals, rejections, connection changes, review links and other important actions are recorded in the workspace's audit log, which admins can review in Settings.

Cookieless visitor stats

Landing-page analytics use no cookies and store no raw IP addresses. A visitor is counted with a keyed hash that changes every day, so people can't be followed across days or sites.

You can delete your data

Disconnecting an account deletes its stored keys and revokes them with the provider. A workspace owner can delete the whole workspace, which removes its content, inbox, files, members and credits and stops billing.

Your data and AI

We don't sell personal data, and we don't use your content to train AI models. The AI receives only what it needs for each task you ask for. The services that help us run Kitewise are listed on our sub-processors page.

Found a security issue? Tell us through the contact form

Try it with your own business

Free plan, no card needed. 1,500 credits every day, and nothing goes out until your team approves it.

Start free