This public security policy describes KGE’s security principles without publishing confidential implementation details that could weaken those controls.

Effective:

1. Identity and access

KGE separates consumer identity from workforce/admin access. Employee and administrative systems should use stronger authentication and role-based access appropriate to their privileges.

2. Data protection

KGE uses access controls, encryption where appropriate, secrets management and least-privilege service identities to reduce unauthorized access to sensitive systems and data.

3. Monitoring and health

Critical services should expose health signals, log meaningful failures and recoveries, and support alerting so operational problems are not discovered only through customer complaints.

4. Auditability

Sensitive administrative actions, support verification, security events and changes to user accounts or virtual-economy records should produce auditable records.

5. Fraud and abuse signals

KGE may use IP, time, user-agent, device/session and behavioral signals to detect abuse or evasion. KGE does not rely on device MAC addresses as an internet identity signal.

6. Vulnerability reports

Good-faith security reports can be submitted through the Contact page using the security/legal inquiry category. Do not exploit or retain data beyond what is necessary to demonstrate a vulnerability.

7. Incident response

KGE may contain, investigate, remediate and notify affected users or authorities when required by applicable law and the nature of the incident.
Important: Product-specific disclosures, app-store rules and rights that cannot legally be waived may supplement or override general language in this policy.