Security and service commitments
Security and service commitments
How we protect access to your business records, what you can do to help, and how to report a concern.
Who can see or change my records?
Kwilo uses signed-in accounts, Workspace membership, roles and permissions to limit who can see or change business records. Businesses remain responsible for inviting the right people, reviewing access and protecting the devices and accounts they use.
What safeguards does Kwilo use?
- The public site and app are delivered over HTTPS.
- Signed-in sessions are tied to the user account and active Workspace.
- Service logs and audit records are used to investigate problems, support users and record important actions.
- Security fixes, maintenance and dependency updates form part of operating the service.
This is a plain-English summary, not a security audit, certification or complete processor list. No online service can guarantee that an incident will never happen.
What information should I add?
Only add information that is needed for the work, the records, support or a legal requirement. Avoid uploading sensitive information that the business does not need to keep in Kwilo.
How do I report a security concern?
Report a security concern to hello@kwilo.co.uk without including unnecessary customer or financial data. Kwilo investigates reported issues and communicates with affected people where the law or service responsibility requires it.
What still needs my judgement?
Your business still needs sensible internal controls and professional advice where appropriate. Make sure the right people check important financial or legal information, including AI-assisted drafts and records, before using it.