Skip to content

Security and trust

Clear controls, honest boundaries

Last reviewed: 22 July 2026

Kinovo is built for private care coordination. Security is a shared, ongoing responsibility: Kinovo designs and operates the application controls, trusted providers operate the underlying infrastructure, and care teams decide what information to add and who should retain access.

Safeguards in the current product

These statements describe controls present in Kinovo today. They are not a guarantee that an online service can eliminate every risk.

Identity and private access

Sign-in, email confirmation and bot protection guard account entry. Private workspace requests are checked against current membership, role and status.

Layered authorisation

Kinovo checks permissions in server actions and database Row Level Security. Sensitive operations use focused database functions that recheck the acting user.

Private file handling

Care-team files use private Storage buckets. Downloads and previews are issued only after workspace and document-visibility checks; files are not published as permanent public links.

Protected connections and browser policy

Normal application traffic uses HTTPS. Kinovo also sends HSTS, content-security, clickjacking, content-type and referrer-policy headers from the application.

Restricted privileged access

Privileged Supabase credentials are server-only and are not intended for browser bundles. Support-admin features are separately allowlisted and audited where the product records an administrative action.

Purpose-limited product analytics

Kinovo uses first-party events and authoritative workspace records to understand product health. Event properties use a fixed catalogue and exclude care content, names, emails, titles, filenames and free text.

Hosting and service providers

Kinovo currently relies on Supabase for database, authentication and private file storage; Render for application hosting; Resend for application email; and Cloudflare Turnstile for bot protection. Some processing may occur outside Australia.

A provider's security certification covers that provider's controls. It does not certify Kinovo, and Kinovo remains responsible for its application design, access rules and operating practices.

What Kinovo does not claim

  • Kinovo is not end-to-end encrypted; authorised application services must process information to provide the workspace.
  • Kinovo does not claim NDIS approval, NDIS certification, HIPAA compliance or a Kinovo SOC 2 certification.
  • Kinovo does not promise that only invited people can ever access information; authorised support, providers or legal processes may require tightly controlled access.
  • Kinovo is not a medical record, emergency service or substitute for clinical and safeguarding systems.

What care-team members can do

  • Use a unique password and protect access to your email account.
  • Invite only people who currently need access and remove them when their involvement ends.
  • Choose the narrowest sensible visibility option for private documents and care protocols.
  • Do not put passwords, payment-card details or unnecessary sensitive information in messages or support requests.
  • Report unexpected access, a lost device or a suspicious invite promptly.

Report a security or confidentiality concern

Email security@kinovo.com.au. Include what happened, when you noticed it and a safe way to contact you. Do not attach care content, passwords or identity documents unless Kinovo asks through an agreed secure channel.

For information handling, access or correction requests, read the Privacy Statement or email privacy@kinovo.com.au.