Security

Last updated: 11 October 2026

KissMySkills is a small company run by its founder in Wrocław, Poland. We can't show you a wall of certificates yet. What we can do is tell you exactly how your data is protected today, what is still missing, and keep this page current. Our Data Processing Addendum commits us not to lower the protection described here.

Infrastructure

  • All KissMySkills apps (AI CRM, the connector for AI assistants, Receptionist, Contracts, the Tools hub, file delivery) run serverless on Cloudflare: Workers for code, D1 for databases, KV for key-value data, R2 for files. We run no servers or operating systems of our own.
  • Cloudflare provides DDoS protection, a web application firewall and bot protection (Turnstile) in front of our apps.
  • Production, staging and test environments use separate databases.
  • The online store runs on Shopify, which handles checkout and payments. We never see card numbers.

Encryption

  • All traffic is encrypted with TLS. The CRM and our sign-in pages send HSTS (one year), so browsers refuse to connect without encryption.
  • Data at rest in databases and file storage is encrypted by Cloudflare.
  • Secrets live in Cloudflare's encrypted secret store, not in source code.

Identity and access

  • No passwords. You sign in with a 6-digit code sent by e-mail (valid 15 minutes, 5 attempts per code, stored only as a hash, with limits on how many codes can be requested per e-mail address and per IP) or a one-tap link.
  • Sessions. The CRM session cookie is host-only, Secure, HttpOnly and SameSite=Lax. Sessions expire after 7 days of inactivity and after 30 days at most. Each session can be revoked on our server: logging out ends it, "log out everywhere" ends all of them, and revoking sessions from the connector ends your CRM sessions too.
  • Connector (MCP). AI clients connect through OAuth with PKCE. Tokens are stored hashed; access tokens last 1 hour, refresh tokens rotate and last up to 90 days (7 days for unverified clients).
  • Workspace isolation. Every database query is scoped to your workspace, your membership is checked again on every request, and invitations only take effect once accepted.
  • Our own access. Internal admin tools are behind Cloudflare Access (owner only) and a second check on our server. Every admin view or export is logged and alerted to the owner. We look at your workspace content only to give support you ask for, to investigate a security incident or abuse, or when the law requires it.

Application security

  • All database queries are parameterised.
  • The CRM and our sign-in pages enforce a Content-Security-Policy with per-response nonces, block framing (X-Frame-Options: DENY), disable MIME sniffing and send no referrer.
  • Write rate limits, storage quotas and field size limits per plan protect against abuse.
  • Webhooks and app-proxy requests are verified with HMAC signatures. Download links are signed and expire.
  • Production dependencies are checked for known vulnerabilities. On 10 October 2026 there were none.

Monitoring and logging

  • The owner gets real-time alerts about sign-in failures, rate-limit breaches, admin access and delivery errors. These alerts contain no names or e-mail addresses: only pseudonymised identifiers, workspace IDs and country.
  • Product analytics run on PostHog's EU cloud in Frankfurt. Users are identified by an internal ID, never by e-mail. Session replays mask all text and inputs, and error reports are scrubbed.
  • Storefront analytics are anonymous: no cookie, a visitor code that changes every day, deleted after 90 days.

AI and your data

  • We do not train AI models on your data.
  • The CRM, Contracts and the connector call no AI models themselves. When you connect Claude, ChatGPT or another assistant, it is your AI client, under your agreement with its provider.
  • Receptionist replies and our tools use open models on Cloudflare Workers AI. Nothing goes to a third-party model provider. See our AI Terms.

Incident response

  • We have a written breach-response runbook with fixed steps for containment, preserving evidence and notification.
  • If a breach affects your data, we tell your workspace admins within 48 hours of becoming aware of it, then keep you updated. Where we are the controller, we notify the Polish data protection authority (UODO) within 72 hours where required.
  • Containment tools ready to use: revoking all sessions at once, rotating signing keys, blocking traffic at Cloudflare's firewall, and rolling back a release in one command.

Vulnerability disclosure

Found a security issue? Please tell us.

  • Report to: security@kissmyskills.com (forwards to the founder).
  • Include: what you found, where, steps to reproduce, and the impact you expect.
  • We will: acknowledge your report within 72 hours, keep you updated, and credit you if you wish once it is fixed.
  • Safe harbor. If you act in good faith under this policy, we will not take legal action against you or report you to law enforcement. Good faith means: you only test against your own account or test data; you don't access, change or keep other people's data beyond the minimum needed to show the issue; you don't degrade the service (no denial-of-service, spam or social engineering); and you give us reasonable time to fix the issue before telling anyone else (we suggest 90 days).
  • In scope: kissmyskills.com subdomains we operate (crm., app., mcp., and other app subdomains) and our Workers. The Shopify storefront itself is run by Shopify; report Shopify platform issues to Shopify.
  • We don't run a paid bug bounty yet.

Subprocessors

The providers that process your data, with location and transfer mechanism, are listed at kissmyskills.com/pages/subprocessors. You can subscribe to change notices there.

Data retention (summary)

  • Delete a CRM workspace: restorable for 30 days, then everything in it, including files and the search index, is permanently deleted.
  • Export: workspace admins can export the full workspace as JSON at any time.
  • Backups: our database platform's point-in-time recovery keeps data for up to 30 days, so deleted data leaves recovery copies within 30 days.
  • Delete your account: yourself, in the CRM under Settings > Profile > "Delete account", or through the connector tool delete_my_account. Deleting your KissMySkills account also deletes your CRM account.
  • Sign-in codes: 15 minutes. Receptionist conversations: 180 days after the last message. Receptionist leads and bookings: 24 months. CRM product usage events: 180 days. Connector usage logs: 12 months. Feedback: 24 months.
  • Full table: retention section of our Privacy Policy.

Compliance and roadmap

Where we are, honestly:

  • GDPR. We are based in Poland; our lead supervisory authority is UODO. We offer a DPA with Standard Contractual Clauses where needed.
  • Certifications. We do not hold SOC 2 or ISO 27001 yet. Our infrastructure provider Cloudflare holds both, among others; that covers their platform, not our application.
  • Not yet in place, planned: external penetration test, public status page, regular restore drills of backups, and SOC 2 / ISO 27001 once the company is larger.
  • Shipped in October 2026: self-service account deletion and automatic retention limits for Receptionist conversations, leads and operational logs.

We'll update this list as items ship. Questions: hello@kissmyskills.com.