TRUST CENTER

Security, privacy and evidence-based operations

KioWare applies identity-aware access, policy enforcement, session isolation, encrypted temporary data, end-to-end audit and consent-based remote support.

Attestation and compliance
ZERO-TRUST EXECUTION CHAIN

Every action passes through identity, policy, state and evidence

IdentityApp · User · Device · Admin
mTLS / TokenMutual trust + scoped claim
PolicyTenant · Session · Capability
Device stateAttested · Ready · Not drifted
EvidenceTrace · Result · Audit
BUSINESS RISK

Security protects revenue, reputation and service continuity

The Trust Center is organized around executive risks: service interruption, privileged access, residual data, configuration drift and compliance evidence.

Privileged accessJIT/PAM and break-glass
Data residueSession-scoped purge
Operational driftConfiguration deviation detection
ContinuityRecovery and DR
JIT PAM and break glass
SECURITY CONTROLS

Platform security commitments

Local-only by default

Device APIs listen locally unless an approved configuration explicitly changes the boundary.

Separated identities

Applications, users, devices and administrators each have their own identity and scope.

Edge policy enforcement

Middleware checks tokens, rights, sessions and device state before every action.

Evidence-ready

Trace IDs, audit events, consent receipts and signing evidence are lifecycle-governed.

PRIVACY BY DESIGN

Kiosk privacy

  • Never store PIN, OTP or passwords
  • Camera/microphone only operate in approved steps
  • Sensitive data is masked during support
  • Temporary data and clipboard are purged at session end
  • No automatic recovery without reauthentication
  • No profile remains visible to the next user
Safe remote support completion
OPERATIONS

Secure operations

Secure release

Signed packages, release rings, canary, rollback and version evidence.

Remote command

Approval, TTL, command scope, result evidence and isolation playbooks.

Remote support

Separate consent, masking, limited rights, audit and revocation.

Recovery & DR

Golden image, backup, restore, checkpoints and DR exercises.

Audit & retention

Minimal logs, scoped access and policy-driven retention.

Incident response

Isolation, alerting, escalation, support bundles and post-review.

PUBLIC FACTS

Company facts & evidence

Certification scope and technical claims must be confirmed for each product, version and deployment contract.

Business registration0313994173
ISO/IEC 27001:2022SIS351224I008
Hotline1900 6884
Security contactinfo@mobile-id.vn
EXECUTIVE BRIEFING · TECHNICAL WORKSHOP

Turn a Kiosk requirement into an auditable delivery scope

Assess TCO, APIs, HAL, IAM, peripherals, PoC, UAT and the production roadmap with the KioWare team.