Keenai maintains the following technical and organisational controls, independently audited under our ISO 27001, ISO 27017, ISO 27018, and SG Cyber Safe certifications:
Encryption in transit (TLS 1.2+) and at rest (AES-256)
Role-based access with least-privilege principles
Multi-factor authentication on staff and client accounts
Segregated production environments with immutable audit logging
Annual penetration testing and continuous vulnerability management
Formal incident-response plan with regulator-notification workflow
Staff training on data handling, phishing resistance, and confidentiality, refreshed annually
While we take all reasonable steps to ensure your personal data is kept secure, we cannot guarantee security during transmission. We use HTTPS (TLS) for all app, web, and payment-processing services. Please keep your account password or passphrase confidential and do not share it with anyone.
We retain personal data only as long as necessary for the purposes set out above, and for the minimum periods mandated by Singapore law. Typically:
A minimum of five (5) years from the end of the client relationship for records supporting regulated financial services and AML obligations
Seven (7) years where required by anti-money laundering or applicable financial laws
Twenty-four (24) months for platform telemetry and usage data
We may retain data for longer because of a potential or ongoing court claim, or for another legal reason. Upon expiry of the applicable retention period, personal data is securely deleted or irreversibly anonymised.