KingDesk
Legal, privacy and trust

Cybersecurity Statement

The security responsibilities, controls and reporting practices protecting KingDesk environments.

Current version

Cybersecurity Statement

Effective: 02 October 2026
Jurisdiction: South Africa

1. Identity and access

Every person must use an individual account. Access is role-based, privilege overrides follow least privilege, tenant data is isolated, sensitive administration is restricted and idle sessions expire automatically.

2. Application and data protection

The platform applies input validation, CSRF controls, prepared data access, secure password hashing, restricted uploads, private evidence delivery, encrypted integration secrets, audit logging and database indexes supporting reliable scoped queries.

3. Operational security

Scheduled maintenance handles session revocation, queue failures, notification archiving and bounded log retention. Administrators should monitor system health, delivery failures, login anomalies and integration status.

4. Customer responsibilities

Customers must promptly disable departed users, review privileges, secure endpoints and email accounts, train users against phishing, maintain accurate emergency contacts, configure HTTPS in production and protect exported reports and printed documents.

5. Incident reporting

Suspected compromise, unauthorized access, lost devices, credential exposure or abnormal transactions must be reported immediately through the authorized support channel. Preserve relevant evidence and avoid altering affected records unnecessarily.

6. Responsible disclosure

Security researchers should avoid accessing personal information, disrupting service or exploiting beyond what is required to demonstrate a concern. Reports should include reproducible details and allow reasonable time for investigation and remediation.

Contact and review

Questions, complaints or data-subject requests should be submitted through the authenticated support channel or to the subscribing organization’s designated Information Officer. This public notice is general information and does not replace an organization-specific agreement or legal advice.