Security
Last updated: October 2026
We take the security of your account and your data seriously. This page summarises the protections we use and what you can do to protect your own account. No online service can promise perfect security, so we describe what we do rather than make guarantees.
How We Protect Your Account
- Encrypted connections: KalHope is served over HTTPS with strict transport security.
- Password protection: passwords are stored only as salted hashes, never in readable form.
- Two-factor authentication (optional): secure your account with an email code or an authenticator app. Authenticator secrets are stored encrypted and backup codes are stored as hashes.
- Account lockout and limits: repeated failed sign-ins lock the account temporarily, and verification and password-reset attempts are limited.
- Rate limiting: applied to sign-in, sign-up, verification, password reset, account recovery, contact, careers and Hope AI to reduce abuse.
- Session controls: you can see your active sessions, end other sessions, and choose to have inactive sessions ended automatically.
How We Protect the Platform
- Content checks on uploaded images.
- Standard security headers, including a Content-Security-Policy that we currently run in report-only mode while we test it.
- Hope AI responses are escaped before they are displayed.
- Periodic review of our code and third-party dependencies for known vulnerabilities.
- Secrets and configuration are kept on the server and are not stored in our public pages or code.
What You Can Do
- Use a strong password that you do not use anywhere else.
- Turn on two-factor authentication in Settings → Security (you will need to sign in).
- Review your active sessions and end any you do not recognise.
- Never share your verification codes. KalHope will never ask for your password or a code by email, chat or phone.
- Be careful about what you put on a public portfolio, because anyone can see it.
Report a Security Issue
If you believe you have found a vulnerability or your account has been compromised, please email info@kalhope.com with the subject “Security” and as much detail as you can (what you found, the page or feature, and the steps to reproduce it). Please give us a reasonable time to fix the problem before sharing it publicly, and do not access or change other people's data while testing.
Related
See our Privacy Policy and GDPR page for how we handle your personal data.