Skip to main content

How does Komashi protect customer data?

Komashi uses encryption in transit, role-based access control, least-privilege administration, activity logs, session management, and monitoring. Backups run daily, weekly, and monthly.

For your customers' personal data, you are the controller and Komashi is your processor. The Data Processing Agreement governs what Komashi may do with that data.

Personal data that you process about your EU/EEA customers is stored, backed up, processed, and accessed exclusively within the EU/EEA, on EU/EEA-established hosting and sub-processors.

Komashi does not store card numbers or payment credentials — see Is customer payment data stored on Komashi?.

note

Two-factor authentication is not available yet — see Can I enable two-factor authentication?.