Kaitier LLC
Who can access Kaitier systems and customer data, and how access is managed.
Last updated July 13, 2026
Version: 1.0 · Effective date: July 13, 2026 · Owner: Joseph Omara, Founder & Managing Member
Review frequency: Annually, or upon significant changes to systems or personnel.
This Access Control Policy defines how Kaitier LLC ("Kaitier") manages access to production systems, customer information, infrastructure, and sensitive business assets.
The objectives of this policy are to prevent unauthorized access to customer information; protect production systems from unauthorized modification; limit access according to business need; and ensure accountability for all administrative access.
This policy applies to employees, contractors, and administrators; cloud infrastructure; source code repositories; production and development environments; third-party integrations; customer financial information; and customer receipt data.
Kaitier follows the Principle of Least Privilege. Access is granted only when required to perform legitimate business responsibilities.
Users receive only the minimum permissions necessary to perform their assigned functions.
Kaitier implements role-based access controls within the application.
Customer: Customers may access only their own account; view only their own receipts and financial information; and manage only their own integrations. Customers cannot access information belonging to other users.
Administrator: Administrative access is limited to authorized personnel. Administrative privileges include system maintenance; production deployment; customer support; security monitoring; and infrastructure management. Administrative privileges are granted only when required.
Every user is assigned a unique account.
Authentication controls include unique user credentials; secure password storage using industry-standard hashing algorithms; session authentication; administrative multi-factor authentication where supported; and OAuth authentication for supported third-party integrations.
Kaitier uses OAuth authorization for third-party integrations, including Google, Microsoft, and Plaid.
Users explicitly authorize access through each provider's secure authorization process.
Kaitier never requests or stores users' banking or email account passwords.
Administrative access is restricted to authorized personnel.
Administrative accounts must use strong passwords; enable multi-factor authentication where supported; and protect credentials from unauthorized disclosure.
Administrative credentials must never be shared.
Access to production systems is limited to authorized administrators.
Production systems include application servers; databases; cloud infrastructure; administrative dashboards; and source code repositories.
Production access is granted only when necessary to support business operations.
Access permissions are reviewed periodically and whenever personnel responsibilities change; administrative privileges change; security incidents occur; or new production systems are introduced.
Unused administrative access is removed promptly.
Access is granted following approval by Kaitier management.
Access is modified whenever responsibilities change.
Access is removed immediately when no longer required.
Application authorization prevents users from accessing records belonging to other customers.
Customer records are logically separated through user-specific authorization controls.
Sensitive information is processed only for authorized business purposes.
Access to third-party services is restricted to authorized administrators.
Services include Google Workspace, Plaid, Microsoft, OpenAI, Resend, domain management, and cloud infrastructure.
Administrative access is protected using multi-factor authentication whenever supported.
Administrative access and security-related activities may be monitored for security investigations; fraud prevention; operational troubleshooting; and compliance purposes.
Any exceptions to this policy require approval from Kaitier management and must be documented.
This policy is reviewed annually or following significant infrastructure changes; security incidents; regulatory changes; or material changes to business operations.
Questions regarding this policy: security@kaitier.com
Approved by Joseph Omara, Founder & Managing Member, Kaitier LLC.
Effective date: July 13, 2026. © 2026 Kaitier LLC. All rights reserved.
Questions? security@kaitier.com