Security & Trust

Your money. Your keys. Your control.

Kronos is built for people who actually use their money — self-employed Americans, freelancers, independent earners. That means we take real responsibility for keeping it safe. Here is exactly how, in plain English.

Server-side authorization Opaque privacy shield Encrypted connections Step-up authentication
At a glance

Four security controls.

App lock

The app covers private content as it leaves the foreground and requires an approved unlock method on return.

Least privilege

Client access is restricted by server-side authorization and database row-level security policies.

Encrypted transport

Supported clients communicate with Kronos services over encrypted HTTPS connections.

Step-up checks

Sensitive flows can require biometrics, a device credential, an account password, or a one-time code.

Security boundaries

The systems behind the app.

Device

Platform secure storage and the operating system protect local credentials and wallet material.

API

Authentication, authorization, validation, rate limits, and idempotency checks run on trusted services.

Database

Row-level security limits data access by authenticated identity and approved service roles.

Financial providers

Provider identity, terms, eligibility, custody, and protections are disclosed in the applicable flow where a rail is available.

Monitoring

Structured error reporting and operational alerts help identify failures without exposing credentials in client logs.

Support

Account and transaction issues can be escalated with identifiers that help trace the affected workflow.

In detail

How it actually works.

Where your money lives

Custody and protections depend on the specific service that is available to your account. Before a supported financial action is confirmed, the product flow identifies the applicable provider and shows the relevant terms, fees, timing, eligibility conditions, and custody model. KronosPay LLC is not a chartered bank.

Crypto custody is yours, not ours

Your crypto wallet is non-custodial. Keys derive on your device from a 12-word recovery phrase that never leaves it — not to our servers, not to our banking partner, not anywhere. We can't move your crypto and we can't recover it for you. That's the point. Back up your phrase from Profile → Secret Phrase the day you sign up, and store it somewhere a fire or a stolen phone can't reach.

Card issuing

Card access is not represented as live until an issuing program is active. The app may show a launch preview or notification option; that does not mean a card has been issued. The issuer, network, fees, eligibility, and protections will be disclosed before enrollment.

Encryption

Kronos uses encrypted connections for supported clients, server-side access controls, and platform secure storage for sensitive device data. Recovery phrases and wallet private keys are not stored in the Kronos application database. Do not share a recovery phrase or account password with anyone, including support.

Biometric & OTP gating

Kronos supports Face ID or Touch ID where available, device credentials, account-password fallback, and one-time codes for selected sensitive actions. Authorization is checked again on the server; a client screen alone cannot approve a transfer.

Compliance

Identity, sanctions, fraud, and payment checks are applied where required by the selected provider and rail. Outbound payment workflows are designed to stop or enter review when a required compliance check cannot be completed; they must not silently treat an unavailable check as approval.

Support, by a real human

In-app support is handled inside Kronos's restricted, first-party support workspace and lands with a real person. Our internal goal is a first response within 4 hours during business hours and 24 hours on weekends. For anything money-related, the in-app error card opens a ticket with the approved diagnostic context attached automatically — such as transfer ID, error code, app version, and screen — so you never have to dig for it.

Account recovery

If you lose your phone, use the supported account-recovery flow and contact support if verification fails. A non-custodial wallet is different: access to its assets depends on the recovery phrase. Kronos cannot recreate a missing recovery phrase, so store it offline and never send it to support.

RECOVERY PATH · LIVE

Status & monitoring

We publish real-time uptime for the parts of Kronos that touch your money: deposits, sends, card auth, P2P, and crypto. Background services (push notifications, marketing email) are tracked separately so a delivery hiccup never gets confused with a money-movement outage.

  • getkronos.io/status — current state per service, the 90-day uptime number where we already have history, and the incident log.
  • Subscribe via the status page to get an email the moment we open an incident.
  • Every deploy is gated behind synthetic checks against the production deposit / send / card flows.
STATUS PAGE · LIVE

Independent reviews

We're a pre-launch fintech. We don't yet have SOC 2 or a public bug bounty, and we won't pretend we do. Here's exactly where we are:

  • Static analysis & dependency scanning — every commit. Live.
  • Third-party penetration test — scheduled within 60 days of iOS public launch. Findings + remediations summarized publicly here.
  • SOC 2 Type I — targeted within 6 months of launch.
  • SOC 2 Type II — targeted within 18 months of launch.
  • Public bug bounty — opens with the iOS launch via a managed platform (HackerOne or Intigriti). Until then, see "Found something off?" below.
CADENCE · POST-LAUNCH

Found something off?

Email security@getkronos.io. Reports of suspected vulnerabilities or unauthorized account activity trigger a same-day review. We acknowledge every report within 24 hours, fix valid issues on a priority schedule, and credit researchers in our public security log when fixes ship. PGP key available on request.

Your money.
Locked tight.

Last updated 2026-05-04 · © 2026 KronosPay LLC