Kronos is built for people who actually use their money — self-employed Americans, freelancers, independent earners. That means we take real responsibility for keeping it safe. Here is exactly how, in plain English.
The app covers private content as it leaves the foreground and requires an approved unlock method on return.
Client access is restricted by server-side authorization and database row-level security policies.
Supported clients communicate with Kronos services over encrypted HTTPS connections.
Sensitive flows can require biometrics, a device credential, an account password, or a one-time code.
Platform secure storage and the operating system protect local credentials and wallet material.
Authentication, authorization, validation, rate limits, and idempotency checks run on trusted services.
Row-level security limits data access by authenticated identity and approved service roles.
Provider identity, terms, eligibility, custody, and protections are disclosed in the applicable flow where a rail is available.
Structured error reporting and operational alerts help identify failures without exposing credentials in client logs.
Account and transaction issues can be escalated with identifiers that help trace the affected workflow.
Custody and protections depend on the specific service that is available to your account. Before a supported financial action is confirmed, the product flow identifies the applicable provider and shows the relevant terms, fees, timing, eligibility conditions, and custody model. KronosPay LLC is not a chartered bank.
Your crypto wallet is non-custodial. Keys derive on your device from a 12-word recovery phrase that never leaves it — not to our servers, not to our banking partner, not anywhere. We can't move your crypto and we can't recover it for you. That's the point. Back up your phrase from Profile → Secret Phrase the day you sign up, and store it somewhere a fire or a stolen phone can't reach.
Card access is not represented as live until an issuing program is active. The app may show a launch preview or notification option; that does not mean a card has been issued. The issuer, network, fees, eligibility, and protections will be disclosed before enrollment.
Kronos uses encrypted connections for supported clients, server-side access controls, and platform secure storage for sensitive device data. Recovery phrases and wallet private keys are not stored in the Kronos application database. Do not share a recovery phrase or account password with anyone, including support.
Kronos supports Face ID or Touch ID where available, device credentials, account-password fallback, and one-time codes for selected sensitive actions. Authorization is checked again on the server; a client screen alone cannot approve a transfer.
Identity, sanctions, fraud, and payment checks are applied where required by the selected provider and rail. Outbound payment workflows are designed to stop or enter review when a required compliance check cannot be completed; they must not silently treat an unavailable check as approval.
In-app support is handled inside Kronos's restricted, first-party support workspace and lands with a real person. Our internal goal is a first response within 4 hours during business hours and 24 hours on weekends. For anything money-related, the in-app error card opens a ticket with the approved diagnostic context attached automatically — such as transfer ID, error code, app version, and screen — so you never have to dig for it.
If you lose your phone, use the supported account-recovery flow and contact support if verification fails. A non-custodial wallet is different: access to its assets depends on the recovery phrase. Kronos cannot recreate a missing recovery phrase, so store it offline and never send it to support.
RECOVERY PATH · LIVEWe publish real-time uptime for the parts of Kronos that touch your money: deposits, sends, card auth, P2P, and crypto. Background services (push notifications, marketing email) are tracked separately so a delivery hiccup never gets confused with a money-movement outage.
We're a pre-launch fintech. We don't yet have SOC 2 or a public bug bounty, and we won't pretend we do. Here's exactly where we are:
Email security@getkronos.io. Reports of suspected vulnerabilities or unauthorized account activity trigger a same-day review. We acknowledge every report within 24 hours, fix valid issues on a priority schedule, and credit researchers in our public security log when fixes ship. PGP key available on request.
Last updated 2026-05-04 · © 2026 KronosPay LLC