Skip to main content
Back to trust centre

Security and service commitments

Security and service commitments

This page explains, in straightforward terms, how Kwilo approaches access control, data handling and day-to-day service security. It is meant to be clear, not overblown.

Content updated 29 August 2026

Access and account control

Kwilo uses signed-in accounts, Workspace membership, roles and permissions to limit who can see or change business records. Businesses remain responsible for inviting the right people, reviewing access and protecting the devices and accounts they use.

Service security basics

  • The public site and app are delivered over HTTPS.
  • Signed-in sessions are tied to the user account and active Workspace.
  • Service logs and audit records are used to investigate problems, support users and record important actions.
  • Security fixes, maintenance and dependency updates form part of operating the service.

What this page does not promise

This is a plain-English summary, not a security audit, certification or complete processor list. No online service can guarantee that an incident will never happen.

Data handling expectations

Only add information that is needed for the work, the records, support or a legal requirement. Avoid uploading sensitive information that the business does not need to keep in Kwilo.

Support and incident handling

Report a security concern to hello@kwilo.co.uk without including unnecessary customer or financial data. Kwilo investigates reported issues and communicates with affected people where the law or service responsibility requires it.

What we are not claiming here

  • We are not claiming that security incidents can never happen.
  • We are not saying software removes the need for sensible internal controls or proper professional advice.
  • We are not saying AI output or records should be accepted without review.

Shared responsibility

Security is partly our job and partly the customer's. Businesses using Kwilo should manage access carefully, review permissions, protect devices and make sure the right people are checking important financial or legal information.