Kardocloud
Trust

Security

What we do to protect the data you and your customers put into the platform — and what we would rather you heard from us than discovered.

Last updated 13 September 2026

Getting in

Accounts are protected by passwords stored as one-way hashes — we cannot read yours, which is why a reset replaces a password rather than sending it to you. Sessions expire. Administrative access inside our team is limited to the people who need it, and what they do is recorded.

Who can watch what

A stream can be open to anyone with the link, or restricted to people you invite. Where it is restricted, invite links expire, and the rule is applied where the media is actually served rather than only hidden in the page — the difference between a policy and a suggestion.

Playback links can be signed and scoped to one viewer and one time window, so a link that leaks stops working.

How long things live

Every kind of stream carries a retention window, and a recording is stamped with the one that applied when it was made — so changing a policy later never quietly shortens what has already been captured. A legal hold exempts a specific recording from deletion entirely, for the times “we delete after ninety days” is the wrong answer.

In transit and at rest

Traffic to and from the platform is encrypted. Stored recordings and files sit on encrypted storage. Credentials issued to clients are short-lived and scoped to one stream, so an intercepted one expires quickly and opens nothing else.

What we are still building

End-to-end encryption for private consultations, single sign-on, and identity verification are in development, and we list them that way rather than implying they are already here. If your use depends on one of them, talk to us about timing before you commit.

Reporting something

Found a vulnerability? Write to hello@kardocloud.com with the subject Security and enough detail to reproduce it. We will acknowledge it, keep you updated, and we will not pursue anyone who reports in good faith and gives us a reasonable window to fix it before going public.

For the security posture of the live streaming product specifically, see Kardolive security.