Security
What we do to keep your account, coins and data safe — and what we’ll never ask you for.
Kita will never ask for
- Your password
- One-time codes (OTP) or 2FA codes
- Your GCash, bank or PayPal PIN
- A fee, deposit or “unlock” payment
We also never message you first on Telegram, WhatsApp or Facebook. If someone does in our name, it’s a scam — tell us.
Your account
- Passwords are hashed with bcrypt before they’re stored. Nobody at Kita can see your password.
- Optional two-step verification with any authenticator app, plus single-use recovery codes. Turn it on under Account → Two-step verification.
- Changing or resetting your password signs out your other devices, and we email you when your password or two-step settings change.
- Log-in, sign-up and password-reset attempts are rate-limited to slow down guessing.
- Session cookies are HTTP-only and stored on our side only as a one-way hash.
Your coins and payouts
- Every withdrawal is reviewed by a person before it’s sent on the scheduled payout day.
- Automatic checks flag payout accounts shared between members, linked accounts and VPN or proxy use, so stolen or farmed coins don’t get paid out.
- Coins are recorded in an append-only ledger. Nothing is edited in place, and every reversal is its own entry you can see in Activity.
- Rewards only arrive through partner callbacks that are signed with a shared secret (and, where partners support it, restricted to their server addresses).
Behind the scenes
- Staff accounts must use two-step verification, and every admin action — approvals, balance adjustments, account changes — is written to an audit log.
- The whole site runs over HTTPS.
- The database is backed up every night.
- You can download or delete your data at any time from Account. See the Privacy Policy for what we keep and why.
Found a vulnerability?
Email [email protected] with “Security report” in the subject, steps to reproduce and the impact. Please don’t access other members’ data, run automated scans that degrade the service, or disclose the issue publicly before we’ve fixed it. We’ll acknowledge your report within a few business days and won’t take action against good-faith research that follows these rules. We don’t run a paid bug bounty yet.