Kehai · Security

Kehai security and data-handling brief

Prepared 5 September 2026 for review with the local website preview. This describes application controls inspected in the repository and the service architecture currently described by the owner. It is not a certification, penetration-test result or verification of a customer's deployed environment.

Service and data flow

Kehai monitors configured official sources for VAT/GST and e-invoicing developments. It prepares drafts for a customer's review; corporate income tax is outside the current offering. It does not calculate transaction tax, submit returns or connect to an ERP merely because a business profile names one.

The service is designed for a separate customer deployment and database. The stated hosting arrangement uses Vercel and Neon, with workspace data stored at rest in the EU. AI inference uses Anthropic in the US. Procurement should inspect the actual deployment region, provider agreements and transfer arrangements for the engagement. EU storage is not a promise that all processing occurs in the EU.

The workspace contains account details, configured sources, business-profile information, retrieved source material, draft assessments, actions and review history. Source material and relevant configured business context can be sent for AI inference. Avoid adding personal or confidential information unnecessary for that assessment.

The public enquiry form collects a work email, source-page attribution and browser user agent. A separate IP record rate-limits submissions. Cal.com receives the email if the visitor continues to the calendar. Resend and Slack can receive enquiry notifications; Sentry is optional error monitoring. The public site uses Vercel Web Analytics for page views and selected interaction events. Film events contain a fixed film identifier and chapter time, not email or workspace contents.

Identity and access

Evidence and integrity

The interface distinguishes source identity, reachability, claim support and human review. A reachable authority page is not proof that a particular obligation applies to a company. Drafts can be wrong and require source checking and the customer's decision.

Review and action events are recorded by the application. Do not describe the database as independently immutable or tamper-proof: this review did not establish a write-once store or independent timestamp service. The normal source fingerprint is a non-cryptographic change-detection value, not a digital signature.

The public captured-source example separately records a SHA-256 digest of one fetched response. It establishes the bytes captured in that example; it does not add cryptographic signing to every workspace record. Evidence exports preserve recorded gaps, including unknown claim support and absent human sign-off.

Application protections

The repository contains role checks, input validation, bounded external fetch controls and HTTP security-header configuration. Public fonts and artwork are self-hosted. The calendar is a third-party frame and AI processing is server-side. The Content Security Policy should be evaluated in the actual deployment; it is not accurate to describe the entire service as having no third-party runtime dependencies.

Automated local checks cover types, lint, regression tests and production compilation. Those checks do not establish operational uptime, successful backup restoration, penetration-test coverage or a formal accessibility standard.

Retention, deletion and exit

The owner confirmed on 5 September 2026 that standard retention/deletion periods for enquiries, terminated workspaces and backups are not yet defined. No universal deletion interval is promised. Account closure should not be taken to mean immediate removal of backup copies.

Before onboarding an engagement with retention requirements, agree the live-data deletion window, export period, provider backup expiry, legal-hold exceptions and who verifies completion. The remaining retention decisions must be resolved before a specific deletion commitment is made.

Contact privacy@kehai.tax for data-rights and deletion requests, or hello@kehai.tax for the deployment evidence required by procurement. The signed engagement agreement should record any assurances beyond this brief.

Contact Kehai · Privacy policy