Trust

Security

How Kasura approaches protecting the data that runs your rental business. This page describes our current practices — not certifications we do not hold.

Last updated: June 25, 20266 min read

Overview

#

Kasura is a multi-tenant SaaS platform for rental businesses. We design the product so each business's data stays logically separated, access is scoped to authenticated users, and sensitive payment data is handled by Stripe — not stored by Kasura.

What we do not claim

Kasura does not hold SOC 2, ISO 27001, or similar third-party security certifications. We do not publish uptime guarantees on this page.

Security is an ongoing process rather than a fixed state. As the Kasura platform evolves, we continuously review operational risks, infrastructure, and development practices to improve the security of the Service.

Infrastructure

#

Kasura runs on managed cloud infrastructure, including Google Firebase and related Google Cloud services for application hosting, authentication, and database storage. Physical security, network isolation, and data-center controls are inherited from those providers.

For a list of third-party services that may process data on our behalf, see Subprocessors.

Infrastructure providers remain responsible for the physical security and resilience of their own facilities. Kasura is responsible for the secure configuration and operation of the Services running on that infrastructure.

Data encryption

#

Data is transmitted over encrypted connections (HTTPS/TLS) between browsers, mobile clients, and Kasura services. Data stored in our cloud infrastructure benefits from encryption at rest provided by our infrastructure providers.

In transit

Encrypted connections

Web and API traffic uses TLS. Do not access Kasura over unsecured networks when handling sensitive business data.

At rest

Provider-managed storage

Database and file storage encryption is handled by our cloud infrastructure providers according to their security standards.

Encryption protects data during transmission and storage but does not replace good security practices such as strong authentication, access management, and careful handling of sensitive information.

Authentication and sessions

#

Account access is protected by email-and-password authentication managed through Firebase Authentication. Passwords are handled by the authentication provider — Kasura does not store plaintext passwords.

Sessions are issued after successful sign-in and are required to access owner and staff areas of the platform. End customers accessing a booking site or customer portal receive separate, scoped sessions tied to their booking context.

Email verification may be required before certain account actions. Multi-factor authentication is not currently offered for all accounts.

Operators remain responsible for protecting account credentials, using strong passwords, and promptly removing access for users who no longer require access to their workspace.

Role-based access

#

Rental businesses can invite team members with scoped access inside their workspace. Permissions are enforced so staff can only perform actions allowed for their role within that business.

Account owners remain responsible for managing who has access, removing former staff, and protecting login credentials for their team.

Permissions are designed according to the principle of least privilege wherever reasonably practical, allowing users access only to the functionality required for their assigned role.

Multi-tenant isolation

#

Kasura is built as a multi-tenant platform: many rental businesses share the same software, but each business's operational data is scoped to its own workspace. Application logic and access checks are designed to prevent one account from accessing another account's data.

Your data boundary

Your bookings, customers, assets, and settings belong to your workspace — not to other Kasura customers.

Kasura regularly reviews application-level authorization logic as new platform features are introduced to help maintain appropriate separation between customer workspaces.

Monitoring and error tracking

#

Kasura uses application monitoring and error tracking (including Sentry) to detect failures, diagnose issues, and improve reliability. Error reports may include technical context such as browser type, page URL, and stack traces.

We aim to avoid collecting unnecessary personal data in diagnostic logs. Monitoring data is used for engineering and support purposes, not sold to third parties.

Monitoring data is retained only for operational, diagnostic, support, reliability, and security purposes and is handled in accordance with our Privacy Policy.

Incident response

#

If we become aware of a security incident that affects customer data, we investigate, contain, and remediate as appropriate. Where required by law or contract, we will notify affected customers without undue delay.

Breach notification for personal data we process on your behalf is described in our Data Processing Agreement. Report suspected incidents to security@kasura.app.

Following a confirmed security incident, Kasura reviews the underlying cause and may implement technical or operational improvements designed to reduce the likelihood of similar incidents in the future.

Responsible disclosure

#

If you believe you have found a security vulnerability in Kasura, please report it to us responsibly. Do not access, modify, or exfiltrate data belonging to other users.

Report a security issue
security@kasura.app

Include steps to reproduce and the affected area
of the platform. We will acknowledge reports in
good faith.

See also our Privacy Policy and Acceptable Use Policy.

Responsible disclosure does not authorize testing against production systems, customer accounts, or infrastructure without prior written authorization from Kasura.

Payments

#

Kasura subscription billing is processed through Stripe. Operators may connect their own Stripe account to accept payments from end customers. See Payment Terms for merchant-of-record roles.

Kasura does not store full payment card numbers for subscription or end-customer checkout. Card data is handled by the relevant payment provider according to their security standards.

PCI

Kasura is not claiming PCI DSS certification on behalf of the platform. Payment security for connected merchant accounts remains governed by each provider's terms.

Operators remain responsible for maintaining compliant payment provider accounts and for following the security requirements published by their chosen payment provider.

Backups and recovery

#

Core platform data benefits from backup and recovery capabilities provided by our cloud infrastructure. Backup frequency and retention are managed at the infrastructure layer.

Operators should maintain their own business records and exports where required for compliance or continuity. Kasura provides data export features where available in the product.

Restoration procedures may be tested periodically as part of operational maintenance. Backup retention periods and recovery capabilities may evolve as platform infrastructure changes.

Availability

#

We work to keep Kasura available and stable, but interruptions can occur during maintenance, provider outages, or unexpected incidents.

No uptime guarantee

Kasura does not offer a published uptime SLA or guaranteed availability percentage on this page. See our Terms of Service for the contractual availability position.

Kasura provides a public status page at /status. During early access, this page provides general service information rather than real-time infrastructure monitoring or historical uptime metrics.

Planned maintenance may occasionally require temporary service interruptions. Where reasonably practical, Kasura will provide advance notice through appropriate communication channels.

Security limitations

#

No internet-connected service can guarantee absolute security. While Kasura implements reasonable technical and organizational safeguards, no security measure can completely eliminate every risk. Operators should maintain appropriate internal security practices, independent backups where appropriate, and business continuity procedures suitable for their own operations.

Your responsibilities

#

Security is shared. As a Kasura customer, you should:

  • Use strong, unique passwords and limit staff access to what each role needs
  • Remove access for team members who no longer work with your business
  • Keep your devices and browsers up to date
  • Review connected payment and integration accounts regularly
  • Contact us promptly if you suspect unauthorized access to your workspace
  • Enable email verification where available and keep account recovery information current
  • Review workspace activity regularly for unexpected changes
  • Report suspected security issues promptly to security@kasura.app
  • Keep connected integrations and payment provider accounts secure

Need help?

Questions about this page?

We're happy to help with anything legal, security or privacy related. Reach out and a human will get back to you.

support@kasura.app