Security
KolayVisa states what it actually does. There are no “military-grade” claims on this page because that phrase describes nothing verifiable.
Development build
This build is a Phase 0 proof. It runs entirely on your machine, connects to no external provider, and is not approved for real applicant data. Only synthetic documents are accepted.
In place today
- A separate 256-bit data key per application, wrapped by a master key (AES-256-GCM envelope encryption).
- Uploaded documents, derived previews and generated packages are encrypted at rest with that key.
- The application record itself — including every extracted value — is encrypted at rest.
- Deleting an application destroys its data key, so surviving ciphertext cannot be read.
- Authorization is enforced in the service layer; the browser can never widen its own scope.
- Uploads are checked by byte signature, not by the declared content type, and scanned before storage.
- Downloads require a short-lived signed grant bound to one object and one application.
- Logs and analytics pass through a redactor that fails closed on anything that looks sensitive.
Not in place yet
Stated so nobody has to guess.
- The master key is an environment variable, not a KMS or HSM key.
- The malware scanner is a signature stub that recognises the EICAR test file; no antivirus engine is connected.
- Extraction is a deterministic reader for synthetic fixtures; no OCR or AI provider is connected.
- Storage is the local filesystem, not an object store with lifecycle policies.
- There is no account system, MFA, or session device management yet.
- No penetration test, DPIA or subprocessor register exists yet.
Provider boundary
Every external capability sits behind an adapter with a declared data-handling policy: extraction, storage, malware scanning and rendering. A provider that cannot state its retention behaviour cannot be selected, and each one has an independent kill switch.