Security & data protection
Built to be trusted with what matters most.
KinMatch handles information about vulnerable children. Safeguarding isn’t a feature we bolted on, it’s the foundation everything else is built on.
UK-hosted database
Your records are held in a UK database (London region). Any supporting services outside the UK are listed transparently in our privacy notice.
Encrypted in transit & at rest
Everything travels over TLS and is encrypted at rest on managed infrastructure.
Role-based access
Every user has a role. People only ever see the records their job needs.
Tamper-evident, independently timestamped
Every action is written to an append-only log, sealed into a cryptographic hash chain, and anchored daily to an independent timestamping authority. Any change, deletion or reordering of a past entry is detectable, even by us. No personal data is used in the seal, and it is ready for Ofsted scrutiny.
Children are initials-only
Children are identified by an anonymised reference and initials, never full names.
Per-organisation isolation
Each organisation's data is strictly separated. Nothing leaks between agencies.
Your data stays yours
Your records are never sold or shared, and stay under your organisation's control. A qualified person always decides.
UK GDPR & a DPA
Built to UK GDPR data-minimisation, with a Data Processing Agreement available for every account.
Our commitments
- Our audit trail is tamper-evident and independently timestamped: every entry is sealed into a cryptographic hash chain, and the chain is anchored to an independent timestamping authority, so any later change to a record is detectable, even by us. Only a hash is ever sent externally, never personal data.
- A Data Processing Agreement is available with every account.
- We do not sell your data, and we never use it to train AI models.
- We’re completing our ICO registration and following ISO 27001-aligned practices as we grow.
- Questions or a security review? [email protected].