Account security
Passwords are hashed on the server. Access tokens remain memory-only while rotating refresh credentials use HTTP-only cookies.
Trust & Security
Kibroo uses layered authentication, authorization, data separation and audit controls without claiming certifications it does not hold.
Passwords are hashed on the server. Access tokens remain memory-only while rotating refresh credentials use HTTP-only cookies.
Owner, Manager, Cashier, Accountant and other roles receive controlled permissions rather than unrestricted access.
Business records and API queries are scoped to the authenticated business to prevent one tenant from reading another tenant's operational data.
Production application and API URLs require HTTPS, and credentialed cross-origin access is restricted to configured Kibroo origins.
Sensitive business, accounting, subscription, Partner and Platform Admin actions create audit records where implemented.
Posted journals require balanced debit and credit totals. Corrections preserve history through reversal or adjusting entries.
Online subscription checkout uses Flutterwave-hosted payment pages and server-side verification. Kibroo does not collect or store raw card details.
Public forms validate inputs, limit submission rates and expose no administrative or Partner financial data.
Kibroo does not claim ISO 27001, SOC 2, PCI DSS certification, NDPC certification, bank-grade security, military-grade encryption or a guaranteed uptime figure.
Take the next step
Contact Kibroo with a general question. Do not send passwords or sensitive payment information.