Security & Trust Center
Kemicard runs inside your Salesforce org, so your passes inherit the security you already trust — and adds wallet-specific protections on top: managed signing, encrypted payloads, fraud-resistant serials, and pass sharing controls.
Our security posture
Salesforce-native posture
Pass data lives on records in your org, governed by your field-level security, profiles, permission sets, IP restrictions, and session policies. There is no second perimeter to audit.
Encryption end-to-end
Pass payloads are encrypted in generation, transit, and at rest. The org communicates with the Kemicard backend through an admin-controlled named credential over TLS.
SOC 2 Type II environment
Kemicard operates inside Salesforce's SOC 2 Type II environment, so your existing compliance posture extends to every pass you issue.
Managed certificates
Kemisoft provisions and renews Apple certificates and Google credentials per client as part of your subscription — tracked so passes never stop updating.
Fraud prevention
Each pass carries a unique serial validated against the source record on every scan. Duplicate scans are detectable, and compromised passes switch to an error-state design that hides the QR.
Audit logging
Every issuance, update, scan, and revocation is a timestamped Salesforce record, reportable with native tools.
Pass Sharing, Screenshots, and Duplicates
- Stateless processing — the Kemicard Server processes each request independently and stores no business data or PII; only minimal request metadata is retained temporarily under strict retention policies, simplifying GDPR/CCPA compliance.
- Scoped OAuth 2.0 — short-lived, tightly scoped tokens through the admin-authorized Connected App govern every Salesforce ↔ server call, with TLS, firewalls, RBAC, and infrastructure-level identity and access management (IAM) on the server side.
- Disable pass sharing — template-level control on Apple; Google share control with device-restriction features.
- Single-device restriction — duplicate installs auto-invalidated on Google Wallet; Apple approach in design, with documented interim patterns.
- Screenshot protection — Google PassConstraints capability, validated with Google's wallet team, on the roadmap.
- Secure private images — Kemicard is among the first Google Wallet partners to implement secure serving of member photos and sensitive imagery.
- Expiry & revocation — fixed or relative expiry, link disabling, and error-state template switching for lost or revoked passes.
Ask us for the security options briefing — including honest guidance on platform-level limits like the absence of rotating barcodes on Apple Wallet industry-wide.
Documentation Your Security Team Can Review
- Security Policy and Client Assurance — platform architecture, data handling, and operational controls.
- Data Processing Addendum — available for review during procurement.
- Responsible AI Usage policy — how Kemicard uses AI, stated clearly.
- End User License Agreement & Acceptable Use Policy — standard commercial terms.
- Salesforce security review — Kemicard is distributed via AppExchange, which requires Salesforce's partner security review.
- GDPR readiness — designed with compliance readiness in mind: secure handling of personal data, privacy-focused digital wallet implementations, and data protection protocols that help organizations meet global expectations.
- SOC readiness — infrastructure and security-management practices aligned with Service Organization Control (SOC) standards, extending the SOC 2 Type II posture of the Salesforce Platform.
Four Layers of Control Over Card Sharing
For high-value cards — benefits, access credentials, paid memberships — Kemicard layers multiple defenses so one card serves exactly one person.
- 1. Wallet-level sharing controls. The first line of defense: configure the template so Apple Wallet and Google Wallet themselves block the built-in share options on the pass.
- 2. Know the iCloud caveat. Apple automatically syncs Wallet passes to other devices signed into the same iCloud account. That's expected behavior for one person's devices — but it's why wallet-level controls alone aren't enough for high-value cards.
- 3. Kemicard multi-device detection. Our proprietary mechanism detects when one card has been installed on multiple devices and changes the card's visual appearance to show it — so the duplicate is obvious at a glance and at the door, where the Scanner also flags it.
- 4. Controlled download links (custom-built). For clients who need it, we can custom-build download-URL policies: the add-to-wallet link invalidates after the first download, after a set number of downloads (say, two), or outside a defined date range.
Agreements & policies
Subscription Agreement
The terms under which Kemisoft Group Ltd. provides the Kemicard Service — definitions, use, term and termination, fees, confidentiality, warranties and liability.
Data Processing Addendum
Applies where personal data is processed through the Service. Request a copy.
Acceptable Use Policy
Referenced by the Subscription Agreement. Request a copy.
Further reading
From the blogBring Your Security Questionnaire
We'll walk your security team through architecture, data flows, and controls.


