Kaitier
Products Plans Security Contact Log in Plans

← Legal & security

Kaitier LLC

Access Control Policy

Who can access Kaitier systems and customer data, and how access is managed.

Last updated July 13, 2026

Official policy Published on kaitier.com

Document information

Version: 1.0 · Effective date: July 13, 2026 · Owner: Joseph Omara, Founder & Managing Member

Review frequency: Annually, or upon significant changes to systems or personnel.

1. Purpose

This Access Control Policy defines how Kaitier LLC ("Kaitier") manages access to production systems, customer information, infrastructure, and sensitive business assets.

The objectives of this policy are to prevent unauthorized access to customer information; protect production systems from unauthorized modification; limit access according to business need; and ensure accountability for all administrative access.

2. Scope

This policy applies to employees, contractors, and administrators; cloud infrastructure; source code repositories; production and development environments; third-party integrations; customer financial information; and customer receipt data.

3. Access Control Principles

Kaitier follows the Principle of Least Privilege. Access is granted only when required to perform legitimate business responsibilities.

Users receive only the minimum permissions necessary to perform their assigned functions.

4. Role-Based Access Control (RBAC)

Kaitier implements role-based access controls within the application.

Customer: Customers may access only their own account; view only their own receipts and financial information; and manage only their own integrations. Customers cannot access information belonging to other users.

Administrator: Administrative access is limited to authorized personnel. Administrative privileges include system maintenance; production deployment; customer support; security monitoring; and infrastructure management. Administrative privileges are granted only when required.

5. Authentication

Every user is assigned a unique account.

Authentication controls include unique user credentials; secure password storage using industry-standard hashing algorithms; session authentication; administrative multi-factor authentication where supported; and OAuth authentication for supported third-party integrations.

6. OAuth Authentication

Kaitier uses OAuth authorization for third-party integrations, including Google, Microsoft, and Plaid.

Users explicitly authorize access through each provider's secure authorization process.

Kaitier never requests or stores users' banking or email account passwords.

7. Administrative Access

Administrative access is restricted to authorized personnel.

Administrative accounts must use strong passwords; enable multi-factor authentication where supported; and protect credentials from unauthorized disclosure.

Administrative credentials must never be shared.

8. Production Access

Access to production systems is limited to authorized administrators.

Production systems include application servers; databases; cloud infrastructure; administrative dashboards; and source code repositories.

Production access is granted only when necessary to support business operations.

9. Access Reviews

Access permissions are reviewed periodically and whenever personnel responsibilities change; administrative privileges change; security incidents occur; or new production systems are introduced.

Unused administrative access is removed promptly.

10. Account Lifecycle

Access is granted following approval by Kaitier management.

Access is modified whenever responsibilities change.

Access is removed immediately when no longer required.

11. Customer Data Protection

Application authorization prevents users from accessing records belonging to other customers.

Customer records are logically separated through user-specific authorization controls.

Sensitive information is processed only for authorized business purposes.

12. Third-Party Services

Access to third-party services is restricted to authorized administrators.

Services include Google Workspace, Plaid, Microsoft, OpenAI, Resend, domain management, and cloud infrastructure.

Administrative access is protected using multi-factor authentication whenever supported.

13. Monitoring

Administrative access and security-related activities may be monitored for security investigations; fraud prevention; operational troubleshooting; and compliance purposes.

14. Exceptions

Any exceptions to this policy require approval from Kaitier management and must be documented.

15. Policy Review

This policy is reviewed annually or following significant infrastructure changes; security incidents; regulatory changes; or material changes to business operations.

16. Contact

Questions regarding this policy: security@kaitier.com

17. Approval

Approved by Joseph Omara, Founder & Managing Member, Kaitier LLC.

Effective date: July 13, 2026. © 2026 Kaitier LLC. All rights reserved.

Other legal pages

Terms of ServicePrivacy PolicyAI & AutomationCookie PolicyAcceptable UseSubprocessorsSecurityData retention

Questions? security@kaitier.com

© Kaitier LLC · The financial OS that keeps every dollar organized.
Privacy Terms AI disclosure Cookies Security Data retention Contact

Kaitier uses strictly necessary cookies and similar browser storage to keep the site secure and working. Kaitier does not currently use optional analytics or advertising cookies. See our Cookie Policy or Cookie preferences.