KolayVisa
English

Security

KolayVisa states what it actually does. There are no “military-grade” claims on this page because that phrase describes nothing verifiable.

Development build

This build is a Phase 0 proof. It runs entirely on your machine, connects to no external provider, and is not approved for real applicant data. Only synthetic documents are accepted.

In place today

  • A separate 256-bit data key per application, wrapped by a master key (AES-256-GCM envelope encryption).
  • Uploaded documents, derived previews and generated packages are encrypted at rest with that key.
  • The application record itself — including every extracted value — is encrypted at rest.
  • Deleting an application destroys its data key, so surviving ciphertext cannot be read.
  • Authorization is enforced in the service layer; the browser can never widen its own scope.
  • Uploads are checked by byte signature, not by the declared content type, and scanned before storage.
  • Downloads require a short-lived signed grant bound to one object and one application.
  • Logs and analytics pass through a redactor that fails closed on anything that looks sensitive.

Not in place yet

Stated so nobody has to guess.

  • The master key is an environment variable, not a KMS or HSM key.
  • The malware scanner is a signature stub that recognises the EICAR test file; no antivirus engine is connected.
  • Extraction is a deterministic reader for synthetic fixtures; no OCR or AI provider is connected.
  • Storage is the local filesystem, not an object store with lifecycle policies.
  • There is no account system, MFA, or session device management yet.
  • No penetration test, DPIA or subprocessor register exists yet.

Provider boundary

Every external capability sits behind an adapter with a declared data-handling policy: extraction, storage, malware scanning and rendering. A provider that cannot state its retention behaviour cannot be selected, and each one has an independent kill switch.

Güvenlik — KolayVisa · KolayVisa