KAMI Workforce
Security & Technical

Built to the standard your IT team expects.

ISO 27001 certified. 99.9% uptime. AES-256 encryption at rest. TLS in transit. Continuous automated security monitoring. This is what enterprise-grade infrastructure looks like — deployed for Philippine SMEs.

ISO 27001
Certified
99.9%
Uptime
AES-256
Encryption
Azure SG
Data residency
System Status

Live. Right now. No guessing.

Real-time status pulled directly from our uptime monitoring. Not a static badge — live data updated every minute.

Checking status…
Last 7 days
Last 30 days
Last 365 days
Architecture

Four principles. No compromises.

Every architectural decision at KAMI is made against these four principles. They're not aspirational — they're the criteria against which every infrastructure change is evaluated.

Elasticity
Decoupled, independent components replace a monolithic architecture. Each module can be updated, scaled, or replaced without affecting the rest of the system — reducing dependency and enabling rapid enhancement.
Performance
High-configuration cloud hosts on Azure and AWS. Redis in-memory caching for hot data and temporary state. Optimised code structure that minimises database queries and handles high-concurrency traffic surges with zero downtime.
Resilience
Multi-tiered redundancy across load balancers, application instances, and databases. High availability RDS with automated failover. Daily off-site database backups with a maximum Recovery Point Objective of 24 hours.
Security
ISO 27001 certified with annual independent audits. Continuous automated security monitoring. AES-256 encryption at rest, TLS in transit, Role-Based Access Control, and daily penetration testing.
Uptime & Resilience

99.9% uptime. Proven over years.

KAMI's infrastructure is designed to keep running — through server failures, traffic spikes, and planned deployments alike. High availability is not a feature. It's the baseline.

High Availability
No single point of failure.
Multi-tiered redundancy infrastructure with elastic load balancing across multiple application instances (ECS). If any single component fails, traffic is automatically rerouted — the system keeps running.
Continuous Operations
Zero downtime deployments.
A multi-stage pipeline — code construction, automated testing, staging, production — ensures every deployment is tested before it goes live. Updates happen without taking any part of the application out of service.
Disaster Recovery
Automated recovery. Hours, not days.
High availability RDS, EC, and Redis deliver near-zero Recovery Time Objective (RTO) in most scenarios. Vendor-agnostic infrastructure means any part of the stack can be replaced within hours. Daily DB backup on a remote site ensures a maximum RPO of 24 hours.
Certification

ISO 27001 Certified.

ISO 27001 is the internationally recognised standard for Information Security Management. It defines how organisations should structure their approach to identifying, assessing, and mitigating information security risks — covering policies, procedures, technical controls, and staff training.

Certification is not self-assessed. KAMI undergoes annual independent audits by an accredited certification body to verify continued compliance. It is renewed — not assumed.

ISO/IEC 27001 Certified
ISO/IEC 27001
Information Security Management
Annual independent audit
Continuous Monitoring

Tested daily. Not just annually.

KAMI uses automated continuous security monitoring tools integrated across its entire tech stack. Daily automated tests run against KAMI’s security posture and surface any deviation in real time — threats are identified before they become incidents.

In addition, KAMI engages independent third-party security firms for annual penetration testing and full security assessments — separate from the ISO audit process.

Integrated across KAMI’s entire tech stack
Daily automated security position testing
Real-time alerts on threats and deviations
Annual independent penetration testing
Infrastructure

How the system actually runs.

All customer data is stored in Azure Singapore. The architecture uses multi-layer redundancy — every component has a fallback, and no single failure can bring the system down.

Internet
Load Balancer
Azure · Elastic
App Server 1
ECS Instance
App Server 2
ECS Instance
App Server 3
ECS Instance
App Server 4
ECS Instance
App Server 5
ECS Instance
Master DB
PostgreSQL · RDS
Replica DB
Auto failover
Daily backup
Remote site · RPO 24h
Redis Cache
In-memory · Hot data
Power
High-configuration resources on Azure and AWS. Market-leading cloud providers — not budget hosting.
Reliability
Elastic load balancing across multiple ECS instances ensures traffic is always routed to healthy servers.
Disaster Recovery
Near-zero RTO in most cases. Any stack component can be replaced within hours. Maximum RPO of 24 hours.
🔒
Security
Continuous monitoring for breaches. AES-256 at rest. TLS in transit. ISO 27001 and ISO 27018 certified.
📍
Data Residency
All customer data stored in Azure Singapore. Never transferred outside the region without explicit consent.
Cost Effective
Efficient infrastructure architecture allows KAMI to pass savings on — enterprise infrastructure at SME pricing.
Your Data

What happens to your data.

Your employees' data belongs to you. Here is exactly where it lives, how it is protected, who can access it, and what KAMI does — and does not — do with it.

Stored in Azure Singapore
All KAMI customer data — employee records, payroll figures, attendance logs, documents — is stored exclusively in Microsoft Azure's Singapore region. It does not leave this region unless you explicitly request it.
Encrypted at rest
AES-256 encryption secures all database instances and snapshots at rest. This is the same encryption standard used by financial institutions and government agencies worldwide.
Encrypted in transit
All data moving between your browser or mobile app and KAMI's servers is protected by Transport Layer Security (TLS). Unencrypted connections are not permitted.
Access controlled by role
Role-Based Access Control (RBAC) operates on the principle of least privilege — every user and system process has access only to what it needs. Access restrictions are enforced at both the interface and backend levels.
Auditable at all times
Every key action within the KAMI system — who did what and when — is recorded in a full audit trail. This is available directly inside your KAMI app for immediate investigation, verification, and compliance purposes.
Never sold. Never shared.
KAMI does not sell customer data to any third party. It is not used for advertising, profiling, or any purpose outside of operating and improving the KAMI platform for your business.
Data Retention

Your data. On a clear timeline.

KAMI retains your data for 90 days after a subscription ends — giving you time to export everything you need before permanent deletion.

90-day retention
KAMI retains customer data for 90 days following the end of a subscription. This window exists to allow customers to retrieve their data or request exports before permanent deletion.
Data export on request
Before your data is deleted, KAMI will provide a full export of your employee records, payroll history, and attendance data in a standard format on request. Raise a request with your KAMI specialist.
Permanent deletion after 90 days
After the 90-day retention window, all customer data is permanently and irreversibly deleted from KAMI’s systems and backups. No residual copies are retained.
Active account data
While your account is active, data is retained for the full duration of your subscription. There are no arbitrary purges of historical payroll or attendance records during an active contract.
Who Can See Your Data

KAMI staff access. The full picture.

We know this is a concern for HR teams — your employee data is sensitive. Here is exactly who at KAMI can access it, when, and under what conditions.

The default
KAMI staff do not access your data.
Your employee records, payroll data, and attendance logs are your business. In the normal course of operations, no KAMI employee views, accesses, or processes your data. It is stored, encrypted, and untouched.
The exception
Access only when you ask for help.
If you raise a support issue that requires KAMI staff to inspect your data to resolve it, access is granted only to the specific person handling your case, only to the data relevant to the issue, and only for as long as the issue requires. You will know this is happening.
The control
Strict internal controls on production access.
Production database and system access is restricted to a small number of senior engineers with explicit authorisation. All access is logged in the audit trail. No engineer has unrestricted or standing access to customer data.
Incident Response

If something goes wrong. Here’s what happens.

No system is immune. What separates accountable providers from unaccountable ones is having a clear, documented response process — and following it. This is KAMI’s.

01
Within 1 hour
Detection & containment.
Automated monitoring detects anomalies in real time. On confirmation of a security incident, the affected system or component is isolated immediately to prevent spread. The on-call engineering team is alerted.
02
Within 24 hours
Customer notification.
If the incident involves customer data, KAMI will notify affected customers within 24 hours of confirmation. Notification includes what happened, what data was involved, and what steps have been taken.
03
Within 72 hours
Regulatory notification.
Where required under applicable law — including the Philippine Data Privacy Act (RA 10173) — KAMI will notify the relevant regulatory authority within 72 hours of becoming aware of a qualifying breach.
04
Post-incident
Root cause & remediation.
A full post-incident review is conducted. Root cause is identified, remediation is implemented, and a written report is available to affected customers on request. Controls are updated to prevent recurrence.
Best Practices

Ten practices. All non-negotiable.

These are the security practices KAMI applies across every layer of its platform. Not aspirational policies — operational standards that are tested, audited, and enforced daily.

Reliable Providers
KAMI exclusively uses reputable cloud providers — Microsoft Azure, AWS, Alibaba Cloud — selected for their advanced secure data storage, encryption standards, and access control capabilities. No unknown or budget infrastructure.
Strong Authentication
Complex password requirements enforced at the system level. Two-Factor Authentication (2FA) available. Facial recognition and biometric fingerprint login on mobile. IP lock capability to restrict access by network location.
Always Encrypted
AES-256 encryption secures all database instances and snapshots at rest — the same standard used by global financial institutions. Transport Layer Security (TLS) protects all data in transit. Unencrypted connections are not accepted.
Access Control
Role-Based Access Control (RBAC) assigns permissions based on the principle of least privilege. Every user — human or system — has access only to what their role requires. Restrictions are enforced at both the interface layer and the backend API.
Audit Trail
Every key action within KAMI is logged — who performed it, when, and what changed. The full audit trail is accessible directly inside the KAMI app. No need to request logs from KAMI — your team can investigate independently.
Continuous Monitoring
KAMI employs Microsoft Defender for Cloud and automated continuous monitoring tools to provide real-time alerting across the entire stack. Any suspicious activity triggers an immediate alert. Security posture is never assumed — it is continuously verified.
Secure APIs
Every KAMI API requires strong authentication and TLS encryption. Database inputs are only accepted from verified KAMI services — no external system can inject data directly. All API endpoints are tested for vulnerabilities as part of the annual penetration testing cycle.
Regular Assessment
Automated tools run daily security tests against KAMI's full infrastructure to identify weaknesses before they can be exploited. In addition, an independent third-party security firm conducts a full penetration test and security assessment every year.
Least Privilege Access
Internal access to KAMI's production code and databases is restricted to a small number of senior engineers with explicit authorisation. No developer has unrestricted database access. All production changes go through a controlled deployment pipeline.
Assume Breach
KAMI's codebase is intentionally highly modular — each component operates independently. This design minimises blast radius in the event of a breach, limiting any attacker's access to a narrow, isolated segment rather than the full system.
Technical Stack

The tools running under the hood.

Every component of KAMI's stack is selected for reliability, security, and performance. No unfamiliar vendors — these are the tools that enterprise engineering teams trust globally.

Front End
Angular
Web application framework
React Native
Mobile application framework
Back End
Python
Core programming language
Django
Python web framework
Operations
Kubernetes
Container orchestration
Microsoft Azure
Content delivery & cloud
Amazon Web Services
Cloud infrastructure
Data Layer
PostgreSQL
Relational database
Redis
In-memory cache
Alibaba Cloud
Cloud storage
Health & Security
Microsoft Defender for Cloud
Real-time threat monitoring
UptimeRobot
Uptime & availability monitoring
Sentry
Error monitoring & alerting
Scout
Application performance monitor
Coveralls
Code test coverage analysis
Project Management
Jira
Agile project management
Confluence
Documentation & collaboration
The KAMI guarantee

If we don’t deliver, you don’t pay.
Simple.

We’ll refund every peso if we fail to deliver any promise made — no questions asked. That’s how confident we are.

Book a demoSee pricing