This public security policy describes KGE’s security principles without publishing confidential implementation details that could weaken those controls.
Effective:
1. Identity and access
KGE separates consumer identity from workforce/admin access. Employee and administrative systems should use stronger authentication and role-based access appropriate to their privileges.
2. Data protection
KGE uses access controls, encryption where appropriate, secrets management and least-privilege service identities to reduce unauthorized access to sensitive systems and data.
3. Monitoring and health
Critical services should expose health signals, log meaningful failures and recoveries, and support alerting so operational problems are not discovered only through customer complaints.
4. Auditability
Sensitive administrative actions, support verification, security events and changes to user accounts or virtual-economy records should produce auditable records.
5. Fraud and abuse signals
KGE may use IP, time, user-agent, device/session and behavioral signals to detect abuse or evasion. KGE does not rely on device MAC addresses as an internet identity signal.
6. Vulnerability reports
Good-faith security reports can be submitted through the Contact page using the security/legal inquiry category. Do not exploit or retain data beyond what is necessary to demonstrate a vulnerability.
7. Incident response
KGE may contain, investigate, remediate and notify affected users or authorities when required by applicable law and the nature of the incident.
Important: Product-specific disclosures, app-store rules and rights that cannot legally be waived may supplement or override general language in this policy.