Security at Kit
Your till, stock, books and payroll live in Kit. This page says, in plain English, how we keep them safe and what we ask of you.
1. Permissions first
Every screen, report and record in Kit is checked against the role and locations of the person who is signed in. An owner sees the whole business; a branch manager sees their branch; a cashier sees the till. Roles are set by your administrator and every change is logged. The same rules apply in the web app, Kit POS Desktop, the phone apps, the TV app and Kit AI.
2. Kit AI cannot see more than you can
Kit AI holds no permissions of its own. When you ask a question it reads records through your login's gates, so the same question gives an owner, a storekeeper and a cashier different answers. When it refuses, it names the rule. Your questions and the records needed to answer them are processed by our AI model provider under a contract that forbids training on them. Conversations can be deleted by you and expire on the schedule your administrator sets.
3. Encryption
- All traffic between your browser, tills, phones and Kit uses TLS 1.2 or later; plain HTTP is redirected.
- Databases, backups and uploaded files are encrypted at rest by the hosting provider.
- Passwords are stored only as salted hashes. Sign-in with Google is supported; two-step verification for administrators is on the roadmap and will be announced here.
- Payment card numbers are never seen or stored by Kit; mobile money is confirmed by the operator and Kit stores the reference and status.
4. Hosting and backups
Kit runs on managed cloud infrastructure with firewalls, separate production and test environments, and access limited to named engineers with hardware-backed keys. Databases are backed up at least daily and kept for 30 days; backups are tested by restoring them. Uptime over the last 12 months was 99.95 %; planned maintenance is announced 24 hours ahead and runs outside East African business hours. See system status.
5. The offline till
Kit POS Desktop keeps a local copy of the till's catalogue and its unsynced sales on the Windows machine, so selling continues when the internet does not. Each sale carries a unique identifier, so a sale can never be counted twice when it syncs, and the office can see each till's sync debt. The installer is signed and updates come only from pos.kit.africa over TLS. Keep the till machine's Windows account locked to the cashier and its disk encrypted with BitLocker where available.
6. EFRIS and payments
For Ugandan businesses using EFRIS, Kit sends exactly the invoice fields the Uganda Revenue Authority requires, over URA's secured interface, and records the fiscal numbers returned. Requests are queued and retried when URA is slow, and every attempt is logged. Mobile money prompts go to MTN, Airtel or the partner bank directly; Kit never holds your customers' money.
7. Who at Kit can see your data
Only support and engineering staff who need access to resolve your case, for the time it takes, with the access logged. We do not look at business records for any other reason, we do not sell them, and we do not use them to train AI models. Staff sign confidentiality agreements and lose access the day they leave.
8. If something goes wrong
We monitor the Service around the clock. If a security incident affects your data we will tell your administrators within 72 hours of confirming it, say what happened and what we are doing, and notify the Personal Data Protection Office where the Data Protection and Privacy Act, 2019 requires it. Incidents are also posted on the status page.
9. What we ask of you
- One login per person. Add users instead of sharing passwords, and remove people the day they leave.
- Give each role only what it needs; review roles when staff change jobs.
- Use a strong, unique password for the owner account and sign in with Google where you can.
- Keep tills, phones and TV boxes on supported, updated operating systems.
- Export your data regularly from inside Kit if your own policy requires a local copy.
10. Reporting a vulnerability
If you find a security problem in Kit, tell us at support@kit.africa with the subject "Security report". We acknowledge within two working days, keep you informed, fix confirmed issues as a priority and thank researchers who report responsibly. Please do not access other customers' data or disrupt the Service while testing.