Security

Last updated: 18 April 2026

Kandan brokers OAuth tokens to your inbox. We take that trust seriously. This page describes concretely how we protect your data. If you find a security issue, please report it responsibly.

Encryption in transit

Encryption at rest

How we handle OAuth tokens

Authentication & sessions

Webhooks

Hosting & infrastructure

Access controls

What we do not do with your data

Software supply chain

Backups

Automated daily database snapshots are retained for 14 days, encrypted at rest, and stored in the same EU region as the primary database. Restores are tested periodically.

Reporting a vulnerability

If you think you've found a security issue, please email security@usekandan.com. We aim to acknowledge within 2 business days and to ship a fix or mitigation as quickly as the issue warrants.

Please:

We do not currently run a paid bug bounty, but credit in release notes is available on request.