Skip to main content
Kemai

Security

Last updated: 2026/10/10

Your customer data is one of your most important assets. This page explains the security measures Kemai currently has in place, so you know exactly how your data is protected.

  1. Encryption in transit

    The Service is available over HTTPS only, including our subdomains and custom domains connected by customers, with HSTS enabled so browsers never connect without encryption.

  2. Workspace isolation

    Every record carries its workspace identifier, and PostgreSQL Row-Level Security enforces isolation at the database level. Even if the application had a bug, it could not read another workspace's data.

    Automated cross-workspace isolation tests run before every release; a release does not ship unless they pass.

  3. Account and sign-in security

    We protect your account as follows:

    • Passwords are hashed with argon2id; we never store passwords in plain text.
    • Repeated failed sign-in attempts are rate-limited to reduce the risk of brute-force attacks.
    • You can sign in with Google; we only receive basic profile information such as your name, email and profile picture.
    • Session cookies are HttpOnly and Secure, and are valid only for the domain you are using; they are never shared with other domains.
    • After signing in, you are only redirected back to domains verified for that workspace, preventing redirects to malicious sites.
  4. Access control

    Workspaces offer owner, admin, member and viewer roles, and workspace admins decide what each member can see and do.

  5. Payment security

    Subscriptions are managed by Recur (recur.tw), and card and other payment details are processed directly by PAYUNi. The Service never handles or stores full card numbers.

  6. Infrastructure

    The application and database run on a managed cloud platform, and the database is not exposed to the internet. All traffic must pass through our edge layer; requests sent directly to the application host are rejected. The site also sends security headers that protect against common attacks such as clickjacking and content-type sniffing.

  7. Reporting vulnerabilities

    If you believe you have found a security vulnerability in the Service, please notify us by email first. Do not disclose or exploit it before we fix it, and do not access or modify other people's data. We will confirm and reply with our progress as soon as possible.

    Reporting details are also published at /.well-known/security.txt.

  8. Contact us

    If you have any questions about this document, or wish to exercise your rights regarding personal data, please contact us:

    Campulse Insight Corp. (領智創匯顧問股份有限公司)

    Tax ID (Unified Business No.): 60535046

    Email: kemai@campulse.tw