Apply Now

Kashable Data Security

At Kashable, consumer data protection is paramount. We protect employee data using bank-level security and strong encryption throughout our infrastructure stack. Sensitive data is stored with trusted banking partners or secure data hosting services. We do not share employee data with third parties for marketing.

Security Assessments & Compliance

Kashable is committed to maintaining the highest standards of security and compliance. We have achieved SOC 2 Type II certification and are PCI-DSS Level 3 certified, reflecting our dedication to protecting consumer data and ensuring the integrity and security of our platform. These certifications demonstrate Kashable's ongoing commitment to rigorous security practices and compliance with industry-leading standards.

Kashable's accreditations include

PCI-DSS Version 4.0 PCI-DSS Version 4.0
SOC 2 Type II SOC 2 Type II
Customer Security Best Practices
Encrypt Data in Transit: Enable HTTPS connections for all web traffic and TLS 1.2 encryption for all socket connections
icon Encrypt Sensitive Data at Rest: Database files are physically encrypted and PII data is persisted in encrypted format
icon Authentication (multi-factor when available) for access to all secured systems
icon Secure Software Development Practices
icon Secure virtual data rooms for exchanging employee eligibility and deduction data
icon Logged and audited access to sensitive data
Cybersecurity Best Practices

Kashable prioritizes comprehensive cybersecurity measures to ensure the protection of our infrastructure and customer data

Daily Vulnerability Scanning We conduct daily vulnerability scans to proactively identify and remediate potential security threats
Annual Penetration Testing Our security posture is rigorously evaluated through annual penetration tests by third-party experts
Static Code Analysis Integral to our secure SDLC, static code analysis maintains high code quality, adhering to stringent security standards.
Intelligent Web Application Firewalls (WAF) With cutting-edge rulesets, our intelligent WAFs protect against sophisticated web-based attacks
Intrusion Detection and Prevention Systems (IDS/IPS) We deploy robust IDS/IPS agents that actively monitor and prevent unauthorized access, ensuring our network's integrity
Data Access & Screening Policies
Role-based access to customer data Role-based access to customer data
 Pre-employment background checks Pre-employment background checks
Company networks isolated behind firewall Company networks isolated behind firewall
Physical records and premises locked when unattended Physical records and premises locked when unattended

Kashable’s policies ensure compliance with state and federal laws relating to lending, privacy, credit reporting, and record retention.

Kashable Security Bounty Program
Kashable Security Bounty Program

At Kashable, we are committed to maintaining the highest standards of security for our platforms and users. Recognizing the critical role that an engaged security research community plays in cybersecurity, we are excited to launch the Kashable Security Bounty Program. This program aims to reward security researchers for their efforts in discovering and reporting potential vulnerabilities in our systems, thereby helping us secure our services and protect our users.

Find Out More