KINDRED

Security Policy

DocumentKindred Security Policy
Version1.0
Effective date15 August 2026
Last updated15 August 2026
OperatorMelco Technology PLC
Contactsecurity@melcotechnology.com

At Kindred, the security and confidentiality of your professional identity, credentials, and contacts are our utmost priority.

This Security Policy outlines the comprehensive technical, architectural, and operational safeguards Melco Technology PLC employs to protect the Kindred platform against unauthorized access, data loss, and cyber threats.


Document Overview & Key Details

DetailValue
DocumentKindred Security Policy
Version1.0
Effective date15 August 2026
Last updated15 August 2026
OperatorMelco Technology PLC
Security Contactsecurity@melcotechnology.com

This document details the security controls, encryption protocols, and incident response measures implemented across Kindred.


1. Architecture & Security by Design

Kindred is built according to "Security by Design" principles. Our architecture enforces strict tenant isolation, multi-layer authorization controls, minimal privilege access models, and continuous automated vulnerability scanning across our containerized microservices.


2. Data Encryption (In Transit & At Rest)

All communications between Kindred clients (mobile and web) and our backend APIs are strictly encrypted in transit using TLS 1.3 and strong cipher suites. Unencrypted HTTP traffic is rejected.

At rest, databases, persistent volumes, and object storage (Cloudflare R2) are encrypted using industry-standard AES-256 encryption.


3. Authentication, Passwords & Access Controls

Account authentication incorporates rigorous protective controls:

  • Passwords are salted and hashed using modern key-derivation algorithms (bcrypt/argon2);
  • One-Time Passwords (OTPs) are cryptographically generated, time-limited, and rate-limited to prevent brute-force attempts;
  • Session tokens utilize secure, HTTP-only, SameSite cookies with automatic expiration and rotation;
  • Multi-factor authentication (MFA) capabilities are supported.

4. Infrastructure, Network & DDoS Protection

Our infrastructure is fronted by global edge networks providing automated Distributed Denial of Service (DDoS) mitigation, Web Application Firewall (WAF) filtering, and bot protection. Backend services operate in private network subnets isolated from direct internet exposure.


5. Vulnerability Management & Responsible Disclosure

We maintain continuous dependency auditing and automated security vulnerability checks in our CI/CD pipelines.

We welcome responsible security research. If you discover a potential vulnerability in Kindred, please report it promptly to security@melcotechnology.com. We investigate all legitimate reports diligently and will not take legal action against researchers acting in good faith.


6. Incident Response & Breach Notification

We maintain a documented Incident Response Plan to detect, contain, and remediate security events. In the event of a confirmed security incident affecting personal data, Melco will notify affected users and the Ethiopian Communications Authority (ECA) in compliance with applicable law.


7. User Security Best Practices

Platform security is a shared responsibility. We strongly advise users to:

  • Use a strong, unique password for your Kindred account;
  • Never share your login OTP or password with anyone — Kindred staff will never ask for your password;
  • Keep your mobile operating system and the Kindred application updated to the latest version;
  • Immediately report any suspicious account activity.