KONTRACKS
Trust · Kontracks

Trust & Security

Last updated June 18, 2026 · The controls, processes, and commitments that protect Customer Data on the Kontracks platform.

Kontracks operates a multi-tenant SaaS platform that handles regulated communications, financial data, and customer relationships for home-improvement service businesses. Security is a foundational engineering requirement, not a feature. The information below describes the controls in place today and what we commit to going forward.

Encryption in transit
TLS 1.2+
All client and sub-processor connections.
Encryption at rest
AES-256
Disk-level for database + backups; column-level AES-256-GCM for secrets.
Tenant isolation
Per-row tenant ID
Application-level enforcement on every query.
Breach notice
≤ 72 hours
From confirmed breach to Customer notification.
RPO
≤ 1 hour
Recovery Point Objective for Tier-1 data.
RTO
≤ 4 hours
Recovery Time Objective for Tier-1 data.

1. Infrastructure

The Kontracks production environment is built on hyperscaler infrastructure operated by SOC 2 Type II–certified providers:

2. Application security

3. Cryptography

4. People & access

5. Software development lifecycle

6. Vulnerability management

7. Business continuity & disaster recovery

8. Incident response & breach notification

9. Vulnerability disclosure

If you believe you have discovered a vulnerability in the Kontracks platform, please report it to security@kontracks.com with as much detail as possible. We acknowledge reports within two (2) business days and aim to remediate confirmed vulnerabilities on the timelines above.

Safe harbor. We will not pursue legal action against a researcher who acts in good faith and within the following limits: (a) does not access or modify data belonging to other Customers; (b) does not perform denial-of-service testing, social engineering, or physical attacks; (c) provides a reasonable opportunity to remediate before public disclosure; and (d) complies with all applicable laws.

We do not currently operate a paid bug bounty, but credit you publicly with permission. Significant impactful reports may be eligible for swag and discretionary acknowledgement.

10. Compliance & assurance

Customers under NDA may request our security questionnaire responses and the SOC 2 Type II reports of our hosting providers by emailing security@kontracks.com.

11. Customer responsibilities

Security is a shared responsibility. Customers are responsible for:

12. Contact

Security: security@kontracks.com
Vulnerability disclosure: security@kontracks.com
Privacy: privacy@kontracks.com
Mailing address: LWR Technologies, Inc. · 390 NE 191st St STE 32488 · Miami, FL 33179 · United States.