Skip to content

Security and privacy

Your family's record. Your keys.

A custody record holds the most sensitive information you have: your children's health, school and daily life. We built KidKept so that you stay in control of it, and we're plain about what the prototype does and doesn't do yet.

AES-GCM share packetsSHA-256 fingerprintsLocal-firstNo ads, no selling, no training

How it works today

Six things we do to protect the record.

You own your data

Your record belongs to you. We only ever get the limited permission needed to store and show it back to you. Export all of it, or delete all of it, whenever you want.

Local-first prototype

Today, your file lives in your own browser's storage (IndexedDB) on your device. It isn't uploaded to our servers, and we can't see it.

Encrypted share packets

Packets are encrypted in your browser with AES-GCM (256-bit). The key is derived from a passphrase you choose using PBKDF2 with a random salt. We never receive the passphrase.

Fingerprinted originals

Every uploaded original gets a SHA-256 fingerprint the moment it arrives. If a single byte changes later, the fingerprint no longer matches, so anyone can check a file is unaltered.

Audit log

Uploads, edits, exports and shares are recorded with a timestamp. You can see what happened to your file and when, and so can the people you choose to show.

Sharing sign-offs

You attest that a packet is accurate before it leaves. The recipient accepts confidentiality before opening it. Every page is watermarked with who it was shared with.

Originals

A fingerprint for every file.

When you add a file, KidKept keeps the original untouched and computes its SHA-256 fingerprint. Summaries, transcripts and tags are stored alongside it, never on top of it. The brief lists each source's fingerprint so a reviewer can verify it independently.

# Source S-52

file counseling_intake_letter.pdf

added 2026-04-15T09:12:44Z

sha256 3b1f7c0e9a4d52f18be6c2d7a90f4e13c5d86b2a7f01e9c4d3a2b5f6e7c809ac

Fingerprint matches the original on file

Sharing

Nothing leaves unless you send it.

Share with your attorney, a GAL, an evaluator, a therapist or an arbitrator, with scope, expiry and sign-offs on both ends. You can revoke a share at any time.

  1. 01

    Choose the scope

    Pick exactly which entries, files and date ranges go in. Nothing else leaves.

  2. 02

    Sign off

    Attest that what you're sharing is accurate to the best of your knowledge.

  3. 03

    Encrypt in your browser

    AES-GCM with a key derived from your passphrase. Set an expiry date.

  4. 04

    Send two ways

    Send the packet one way and the passphrase another, like a text and an email.

  5. 05

    Recipient accepts

    They agree to keep it confidential before it opens, then see a watermarked copy.

Our pledge

We will never train AI on your record.

AI analysis is opt-in and file by file. When you use it, your content is processed only to give you the result. Our AI providers are contractually bound not to train on it, and to keep zero or minimal retention where that option exists.

  • No selling your data, ever
  • No advertising, and no ad tracking
  • AI is off until you turn it on
  • Full export and full deletion, any time

What local-first means for you right now

  • We can't see, recover or back up your file. If you clear your browser data or lose the device, it may be gone. Export regularly.
  • Anyone who can use your browser profile may be able to see your record. Lock your device and avoid shared computers.
  • Send a share passphrase through a different channel from the packet itself.

Production roadmap

Where security goes from here.

Planned before general availability. We'll publish progress on this page.

Encrypted cloud sync

Planned

Optional sync across devices, encrypted in transit and at rest, with per-file keys and backups.

Multi-factor authentication

Planned

Authenticator app and passkey sign-in, with alerts for new devices and suspicious logins.

SOC 2

Planned

Independent audit of our controls: Type I first, then Type II, plus regular third-party penetration tests.

Legal-process transparency

Planned

If anyone demands your data, we'll tell you (unless legally barred), send them to you first and hand over as little as possible.

Found a security issue? Please write to security@kidkept.com. We appreciate responsible disclosure.

See it for yourself.

The demo case runs entirely in your browser. Nothing you do there leaves your device.