Security & data protection

Built to be trusted with what matters most.

KinMatch handles information about vulnerable children. Safeguarding isn’t a feature we bolted on, it’s the foundation everything else is built on.

UK-hosted database

Your records are held in a UK database (London region). Any supporting services outside the UK are listed transparently in our privacy notice.

Encrypted in transit & at rest

Everything travels over TLS and is encrypted at rest on managed infrastructure.

Role-based access

Every user has a role. People only ever see the records their job needs.

Tamper-evident, independently timestamped

Every action is written to an append-only log, sealed into a cryptographic hash chain, and anchored daily to an independent timestamping authority. Any change, deletion or reordering of a past entry is detectable, even by us. No personal data is used in the seal, and it is ready for Ofsted scrutiny.

Children are initials-only

Children are identified by an anonymised reference and initials, never full names.

Per-organisation isolation

Each organisation's data is strictly separated. Nothing leaks between agencies.

Your data stays yours

Your records are never sold or shared, and stay under your organisation's control. A qualified person always decides.

UK GDPR & a DPA

Built to UK GDPR data-minimisation, with a Data Processing Agreement available for every account.

Our commitments

  • Our audit trail is tamper-evident and independently timestamped: every entry is sealed into a cryptographic hash chain, and the chain is anchored to an independent timestamping authority, so any later change to a record is detectable, even by us. Only a hash is ever sent externally, never personal data.
  • A Data Processing Agreement is available with every account.
  • We do not sell your data, and we never use it to train AI models.
  • We’re completing our ICO registration and following ISO 27001-aligned practices as we grow.
  • Questions or a security review? [email protected].