Security
Security at Do Kaudi.
Do Kaudi handles investor contacts, meeting notes, and price-sensitive information. Here is how we keep that data protected. We describe only what we actually do.
Company-specific access
Uploaded shareholder registers require an explicit access grant for each company. Public exchange disclosures are available separately. Deployment arrangements, hosting region, and any dedicated infrastructure requirements are confirmed during onboarding and documented in your agreement.
Production infrastructure
Our production application runs on DigitalOcean App Platform, with its database on DigitalOcean Managed MySQL. Some optional features send relevant data to the sub-processors identified in our privacy policy.
Encryption
The production website uses HTTPS and HTTP Strict Transport Security (HSTS). Database transport and storage protections are part of the deployment configuration reviewed during onboarding.
Access control
Roles control administrative capabilities. Access to an uploaded shareholder register also requires permission for its company, including for administrators. Access to one company does not grant access to a peer company's register.
Authentication
New passwords are hashed before storage. Login endpoints are rate-limited to slow down credential-guessing attacks, and the application uses CSRF protection to guard against cross-site request forgery. Contact support if you need help recovering access.
Responsible disclosure
If you believe you have found a security issue, we would like to hear from you. Please email [email protected] with the details so we can investigate and respond. We appreciate reports made in good faith and will work with you to confirm and address genuine issues.