Security & Privacy

Your data is safe with us.

We take the protection of your personal and medical information seriously. Here is how we keep it safe.

Approved contacts only. A closed system.

The Ken only accepts calls and messages from contacts that you, the family member, have explicitly approved through the portal. There is no email on the device, no web browser, no app store, and no way for an unknown caller or sender to reach them.

This closed-contact model is our primary defence against telephone fraud, scam calls, and phishing messages. If a person is not on the approved contact list, they cannot make contact. You can add or remove contacts remotely at any time from the family portal or the app.

If the device is lost or stolen, the data doesn't go with it.

Messages, voicemails, contacts and photos stored on the device are kept in an encrypted partition that can only be unlocked with a passphrase we hold in the cloud. The device fetches that passphrase fresh on every boot. If someone removes the SD card and mounts it on a laptop, all they see is ciphertext.

Nobody sits between your Ken and us.

Everything the device sends to us is pinned to the exact public keys we control. An attacker on your WiFi can't silently impersonate our servers, even with a valid-looking HTTPS certificate from elsewhere.

Who gets in is who you've invited - nobody else.

Medical information is always protected.

Medical information, personal identifiers, and anything else sensitive are encrypted at the field level before they're stored - separately from the general database - and accessed only through a documented audit trail.

Found a security issue? Tell us.

We welcome reports from security researchers and members of the public. If you believe you have found a vulnerability in The Ken device, the portal, the family app, or our cloud services, please contact us before disclosing it publicly.

How to report

Email [email protected] with a clear description of the issue, the steps to reproduce it, and the potential impact. A machine-readable copy of this policy is published at /.well-known/security.txt.

What we promise

  • We will acknowledge your report within one working day
  • We will give you a substantive response within five working days
  • We will keep you informed as we work on a fix
  • We will credit you publicly on this page if you wish, once the issue is resolved
  • We will not take legal action against researchers who report in good faith and follow this policy

What we ask

  • Give us a reasonable time to fix the issue before disclosing it publicly. Ninety days is our default, less if the issue is already public, more if the fix is genuinely complex
  • Do not access, modify, or delete data that does not belong to you
  • Do not run automated scanners against the production environment without prior agreement
  • Do not test denial of service, social engineering, or physical attacks
  • Do not publish or share the issue until we have agreed it is safe to do so

Out of scope

  • Issues in third-party services we use (Cloudflare, Resend, Stripe) - please report to the vendor directly
  • Reports generated solely by automated scanners with no demonstrated impact
  • Missing security headers without a demonstrated exploit
  • Self-XSS, clickjacking on pages without sensitive actions, or rate limiting on non-authentication endpoints

We keep your Ken patched for at least five years.

Every Ken receives security updates over the air. Updates are signed by us, verified by the device, and apply automatically. There is nothing for you to do.

Our commitment. We will provide security updates for every Ken sold from the date of purchase, for a minimum of five years. We expect to provide them for longer; five years is the floor. If we ever change this commitment, we will publish the change here with at least three months' notice for affected devices.

What gets patched. Updates cover the device's operating system, the application running on it, our cloud services, our companion app for iOS and Android, and the family portal. A vulnerability in any layer can affect the others, so all five are kept current together.

How we communicate updates. Critical security fixes are deployed automatically and silently. Material changes (new features, changes to data handling, changes to update cadence) are announced by email to the registered account holder and posted on this page.

This statement satisfies our obligations under the UK Product Security and Telecommunications Infrastructure Act 2022 (PSTI) and the equivalent EU Cyber Resilience Act provisions.

Your privacy matters.

We collect only what is needed to operate The Ken and keep they connected. All personal and medical data is encrypted, stored in EU data centres, and never shared with advertisers or AI services.

Our full Privacy Policy is available at Privacy Policy.

Terms of use.

By using The Ken device and portal, you agree to our terms of service. These cover your subscription, our responsibilities, data handling, and your rights under UK consumer law.

Our full Terms & Conditions are available at Terms & Conditions.