Security at Kittum

Careful access for sensitive financial work.

Security starts with a simple question: should this person be able to see or change this company’s information right now? Kittum is designed to make that answer visible and enforceable.

The foundation

Access, records, and recovery are part of the product.

Verified access

Accounts, contact methods, session checks, and staff roles are designed around a known person rather than a public file link.

Company separation

Users receive access to the companies and work they need. One client’s records do not become visible through another client’s workspace.

Visible change history

Important actions keep the person, time, company, prior value, new value, and reason needed for review.

Documents and recovery

Uploads are checked, tied to the right account, limited by role, and retained with review history. Operational data also needs tested backups and restoration procedures.

Protected system credentials

Service credentials belong in managed systems with limited access, rotation, and revocation rather than source files or shared notes.

Current availability

Real taxpayer and payroll data waits for a separate production release.

The public site collects no client documents. The portal remains limited to fictional data while production storage, agreements, staff access, monitoring, recovery, and incident procedures are completed and tested.

Public site

Product information and ordinary business contact only.

Private testing

Fictional companies, employees, documents, transactions, and pay runs.

Production

Requires a separate reviewed environment and explicit release before real client use.

Have a security or privacy question?

Ask us about a specific control or concern. Please do not include client records, credentials, bank information, or exploit details in the first email.