Platform · Security & trust

Serious about the sensitive parts

Payroll, patient files, tenants, invoices: our products hold the things a business can least afford to leak. Security is part of the platform, not a premium tier.

app.kolab.mu/settings/audit Activity log+ NewSearch…ACTORACTIONMODULEWHENK. RamsamyApproved leave: 3 daysLeave2 min agoSystemBackup completed: 412 MBBackups1 h agoP. DoorgahEdited pay rate: Rs 85 to Rs 92PayrollYesterdayA. ChettyBlocked device: Front kiosk 2SecurityYesterdaySystemRestore drill: PASSBackups12 Jul

Passwordless sign-in

Passkeys, one-time codes and TOTP instead of sticky-note passwords. Roles decide who sees what, and the server enforces it, not just the screen.

Audit trails everywhere

Append-only logs record who did what, when, from where, with before-and-after values on every sensitive change. Corrections are reversals, never silent edits.

Backups that restore

Encrypted backups on two independent providers, retention tiers from hourly to forever, and twice-yearly restore drills that prove the backups actually work. A backup nobody has restored is a hope, not a plan.

Lost-device protection

Shared tablets and kiosks can be blocked, signed out or remotely wiped. Devices that stay offline too long lock themselves. A stolen phone is an inconvenience, not a breach.

Honest about limits

We document what is enforced server-side versus on the device, and we never sell theatre. If a control has a limit, the documentation says so in plain words.

Questions

Asked all the time

Who can see salaries?
Only roles you grant. Sensitive tables like payroll are isolated server-side; hiding a page in the app is never the only protection.
Can we export everything?
Yes, at any time, in open formats. Your data is yours; export and deletion are self-service, and DSAR requests have dedicated tooling.

Security & trust comes with every product

Platform promises are not premium tiers. Every Kolab product ships with all of them, from the first staff member.

Book a demo