Kronos Console

Owner & support operations sign-in. Access is role-scoped and audit-logged.

Sessions expire after two hours.
Never approve an MFA prompt you didn't initiate.

Kronos Console

Confirm it is you

Enter the code from your authenticator app.

MFA enrollment QR code

TOTP multi-factor protects treasury and customer data access.

Kronos Console
Overview
Connecting
Console
Support desk
Owner tools

Overview

Wallet liability
loading
 
Active transfers
loading
 
Open ops withdrawals
loading
 
Unacknowledged drift
loading
 
Open requests
loading
Waiting across support & operations
App chats open
loading
Live conversations from the Kronos app
Website chats open
loading
Live conversations from getkronos.io
Customers
loading
 
Work queues
Jump to work

Everything the team works in lives in this console — inbox, calls, customers, money, compliance, travel and incidents.

Compliance

Identity review queue — checks the automated decision routed to a person. Every action here is audited.

Identity review

Only checks that need a person appear here. Evidence links expire 30 minutes after opening.

0 waiting
ReceivedCustomerCheckAutomated resultAction
Open Compliance to load reviews.

Transactions

Money activity across the product. Filters run server-side.

CreatedPostedCustomerTypeAmountStatusDescription
Open Transactions to load activity.

Customers

Verified customer directory. Open a customer for identity verification and compliance escalation.

EmailNameKYCTierStatusBalance
Open Customers to load the directory.

eSIM cases

Reissue is a free replacement, refund credits the customer once and opens the eSIM Access cancel/reclaim path. Reclaim status tracks the provider side of that credit.

CreatedCustomerIssueeSIMStatusReclaimActions
Open eSIM to load cases.

Incidents

Incident response with the 48-hour postmortem review library.

Declare incident
IncidentSeverityStatusServices48-hour review
Open Incidents to load the register.
Incident review

Action items
Similar incidents

Policies

Company policies — owner review. Draft v2/v3, generated from the shipped controls on 2026-08-05. Review here first; distribute to support & compliance staff once approved.

KronosPay LLC — BSA/AML Program Policy (v3)

Owner: Compliance Officer  ·  Approved by: Founder/Managing Member  ·  Effective: August 5, 2026  ·  Review cycle: Annual, or upon material product change


1. Purpose & Scope

This policy establishes KronosPay LLC's ("Kronos") program to detect, prevent, and report money laundering, terrorist financing, sanctions evasion, and fraud. It applies to all Kronos products (the Kronos app, cards, transfers, crypto features), all employees and contractors, and all markets we serve. Kronos operates on a partner model: regulated banking, custody, and payment rails are provided by licensed partners (collectively "banking partners"), whose compliance requirements Kronos enforces upstream. Where this policy and a partner's requirement differ, the stricter applies.

2. Governance

  • A designated Compliance Officer (CO) administers this program, with direct escalation to the Founder. The CO has authority to freeze accounts, hold verifications, and block transactions without prior business approval.
  • Compliance staff operate in a dedicated, least-privilege workspace (the Kronos support/compliance console) with individually assigned accounts, mandatory authenticator MFA, scoped permissions, and a complete access audit trail. Compliance capabilities (identity review, linked-account analysis, device/IP history) are gated behind the `identity_review` permission scope.
  • This policy is reviewed at least annually and whenever geographic availability, products, or partners change.

3. Customer Identification Program (CIP / KYC)

Every customer must complete identity verification before accessing money movement. The program collects and verifies:

  1. Identity data: legal name, date of birth, residential address, country of residence, and tax identification number (SSN/ITIN for US persons; national tax/ID number elsewhere).
  2. Phone verification: SMS one-time-code verification of the customer's mobile number; the verified number is bound to the account and must match the number submitted for KYC.
  3. Government ID documents: passport, driver's license, national ID, or residence permit, captured in-app with automated capture-quality checks (screen-capture/photocopy detection, glare/crop/readability checks). Each accepted image is cryptographically bound (SHA-256) to its quality-check receipt; any byte change invalidates the submission.
  4. Proof of address where the ID does not carry one.
  5. Live biometric check: a randomized three-pose live video and centered selfie, compared against the ID portrait by an automated model under a one-use server-issued session. Only a clear pass releases the application; every inconclusive or failed result is staged inside Kronos for human compliance review and reaches the banking partner only on explicit reviewer approval with a written note.
  6. Partner review: the banking partner performs the authoritative KYC/sanctions review and issues the final approve/reject/RFI decision. Kronos mirrors that decision and notifies the customer. Customers have no account functionality (no rails, no balances-in-motion) until partner approval.

Risk-based step-up: a server-side risk engine forces an additional spoken-challenge verification when exceptional risk signals fire — failed device attestation, impossible travel, recent SIM swap, IP-country vs. declared-residence mismatch, reuse of identity signals from another account, or repeated inconclusive checks. Step-up outcomes that use the accessibility fallback always route to human review.

4. Sanctions & Geographic Restrictions

  • Kronos does not onboard residents of jurisdictions subject to comprehensive sanctions or prohibited by our banking partners: Cuba, Iran, North Korea, Russia, Syria, Venezuela.
  • Kronos additionally does not onboard residents of countries our banking partners cannot review (the partner "not supported" list, ~66 countries). Both lists are enforced at signup against the declared residence and the signup IP country, in the KYC document flow, and server-side at submission. The lists are maintained in one shared code module and synchronized with the partner's published policy.
  • Partner-side sanctions/PEP/watchlist screening applies to every submitted application; watchlist hits route to a dedicated review state that blocks account access pending disposition.

5. Duplicate Identity & Fraud Controls

  • Identity graph: SHA-256-peppered fingerprints of documents, tax IDs, phones, addresses, and payment credentials are recorded per customer. A KYC submission that matches another account's document image or tax ID is hard-blocked before it reaches the banking partner. Reviewers can query linked accounts (shared documents, tax IDs, phones, addresses, devices, sign-in IPs) directly in the compliance console; every query is audit-logged.
  • Device & session integrity: iOS App Attest / Android Play Integrity attestation, trusted-device registry, device approval for new devices/locations on verified accounts, and login-attempt capture (IP, device hash, user agent, outcome).
  • One-identity binding: biometric check receipts are single-use, hash-bound to the exact ID and selfie bytes submitted, claimed atomically, and consumed on submission — a receipt cannot be replayed or attached to different documents.

6. Transaction Monitoring

  • All ledger activity is reviewable in deposit (money-in) and withdrawal (money-out) queues with created and posted timestamps, per-customer history, and status filters.
  • A real-time fraud decision engine evaluates velocity, device, recipient-novelty, and integrity signals on money movement; high-risk actions require step-up verification (passkey or spoken liveness) above configured thresholds (e.g., high-value withdrawals/purchases, payout-destination changes).
  • The CO and authorized staff may freeze accounts immediately; unfreezing, recovery links, and device resets additionally require a live identity verification completed within the preceding 30 minutes and an open assigned case.
  • Support balance adjustments require independent second-person review; the requester can never approve their own adjustment.

7. Reporting & Escalation

  • Suspected structuring, layering, identity fraud, sanctions evasion, or unexplained activity must be escalated to the CO the same business day via the compliance case system. Staff must never disclose to a customer that they are under review ("no tipping off").
  • Kronos cooperates with its banking partners on regulatory filings (including SAR-equivalent reporting) and provides supporting evidence through authenticated channels only — never email attachments.

8. Records & Retention

  • CIP records, verification evidence, and decision notes: 5 years after account closure. Transaction records: 7 years. Records are stored encrypted; identity evidence is accessible only through time-limited signed links (30 minutes) inside the audited console.
  • Reviewer decisions require a written note (minimum 8 characters) and are permanently associated with the exact evidence reviewed.

9. Training & Independent Review

  • All workforce members complete AML/KYC training at onboarding and annually; compliance staff additionally train on evidence handling and this policy.
  • The program is independently tested at least annually (internal audit or qualified third party); findings are tracked to closure by the CO.

KronosPay LLC — Information Security Policy (v2)

Owner: Founder/Managing Member (security) with the Compliance Officer  ·  Effective: August 5, 2026  ·  Review cycle: Annual, or after any material incident


1. Scope

Applies to all Kronos systems (mobile app, APIs/edge functions, databases, dashboards, marketing site), all data classes (customer identity data, biometric evidence, financial records, credentials), and every employee/contractor with access to any of them.

2. Access Control

  • Least privilege by scope. Workforce access is granted through named permission scopes (tickets, fraud, voice, customer read, transactions read, identity review, account controls, compliance manage, etc.). Staff receive only the scopes their role requires; sensitive views (identity evidence, device/IP history, linked accounts) require the compliance-grade scope and are denied otherwise.
  • Workforce identity is separate from customer identity. Staff use dedicated workspace accounts with verified work email, server-verified sign-in, and mandatory authenticator (TOTP) MFA at AAL2. Support sessions expire after 2 hours and require full re-authentication.
  • Single-use, out-of-band grants. Workforce invites and account overrides are single-use and consumed server-side on first use; re-shared links are inert.
  • Customer device trust. New devices/locations on verified accounts require explicit device approval; staff can revoke trusted devices only with an open assigned case and recent live identity verification of the customer.
  • Access auditing. Every sensitive access (identity evidence views, security-context views, linked-account queries, account actions) writes an immutable audit row (actor, target, action, reason, timestamps). Admin-actor IPs are logged.

3. Data Protection

  • Encryption. TLS 1.2+ in transit everywhere; provider-managed encryption at rest (database, storage). Secrets live in the managed secret store/vault — never in code. A pre-commit secret scanner blocks credentials from entering the repository.
  • Biometric & identity evidence. Captured under one-use server sessions; hash-bound (SHA-256) to their review receipts; stored in private buckets; accessible only via signed URLs with a 30-minute TTL issued inside the audited console; never attached to email or exported. Client-side, biometric material lives only in volatile memory and is zeroed after upload — it is never written to on-device storage.
  • Data minimization. Tax IDs and document numbers are excluded from the profile store; the identity graph stores only peppered hashes, never raw values; device fingerprints are truncated before display.
  • Retention & deletion. Account records 5 years post-closure; transactions 7 years; shorter-lived artifacts (verification sessions, signed links, attestations) expire automatically. Deletion requests honor statutory AML retention carve-outs, which are disclosed to the requester.

4. Application & Infrastructure Security

  • Server-side enforcement. All authorization, validation, sanctions/country policy, and money-movement gates are enforced in edge functions with the service role; clients are never trusted. Row-level security separates customer data access.
  • Idempotency & receipts. Every provider-affecting KYC/money operation runs under a durable operation receipt with deterministic idempotency keys; ambiguous outcomes pause for review rather than retrying blindly. Webhooks are signature-verified and replay-deduplicated.
  • Rate limiting on authentication, verification, and submission endpoints (durable, per-user/IP).
  • Hardened dashboards. The admin and support consoles ship strict CSP, frame-denial, no-referrer, and no-store headers; evidence pages force re-authentication on expiry.
  • Fail-closed operations. Deploy paths to decommissioned infrastructure exit non-zero; a signups kill-switch can pause onboarding instantly; deprecated endpoints return 410.
  • Device integrity. iOS App Attest and Android Play Integrity verify app/device authenticity. Verifier infrastructure failures are recorded as `unsupported` — they inform, but never substitute for, customer-adverse decisions; genuine attestation rejections trigger risk step-up.

5. Monitoring & Incident Response

  • Function logs, webhook receipts, fraud decisions, and audit tables are monitored; incident tooling pages the Founder on critical failures.
  • Incident process: contain → assess scope → remediate → notify. Confirmed breaches of personal data are notified to affected users and regulators per applicable law (and within GDPR's 72-hour supervisory window where it applies). A post-incident review with tracked actions is mandatory.
  • Staff must report suspected incidents (lost device, phishing, credential exposure, data mishandling) to the Founder and CO immediately; good-faith reporting is never penalized.

6. Vendor & Partner Management

Processors and partners (cloud/database, CDN/hosting, banking partners, SMS, identity-model provider, email) are inventoried with data-processing agreements and transfer mechanisms (SCCs + UK addendum where applicable). New vendors touching customer data require Founder + CO approval. Partner API credentials are scoped, stored in the secret manager, and rotated on personnel change or suspected exposure.

7. Workforce & Endpoint Rules

  • Individual accounts only; credential sharing is prohibited and is a terminable offense.
  • Work on updated devices with screen lock; no customer data on personal storage, messaging apps, or screenshots. Identity evidence is viewed only inside the console.
  • Contractor onboarding includes identity verification, engagement classification, and explicit workspace approval before any access is granted; offboarding revokes workspace access, voice credentials, and scopes the same day.

8. Exceptions

Any exception to this policy requires written Founder approval with a compensating control and an expiry date, recorded in the compliance case system.

Kronos Workforce Handbook (v2)

For: all Kronos employees and contractors (support, compliance, fraud, QA, PA)  ·  Effective: August 5, 2026

Welcome to Kronos. We move people's money and hold their identities — the two most sensitive things a company can be trusted with. This handbook is how we keep that trust. Read it fully; you'll confirm acceptance in the workspace.


1. How we work

  • Customer money and identity come first. When speed and safety conflict, safety wins. Escalate rather than guess.
  • Everything is audited — work like it. Every sensitive view and action you take in the console writes a permanent audit record with your name on it. That's protection for you as much as for customers: a clean audit trail is how we prove you did the right thing.
  • Honesty is non-negotiable. Report mistakes immediately — a reported mistake is a fixable event; a hidden one is a firing offense.

2. Your workspace account

  • You sign in at dash.getkronos.io with your individual Kronos work identity: verified work email + authenticator (TOTP) MFA. Sessions expire after 2 hours; you'll re-authenticate.
  • Your access is scoped to your role (tickets, fraud, voice, customers, transactions, identity review, compliance). If a button errors with a permission message, that capability isn't part of your role — ask, don't work around it.
  • Never share credentials or approve an MFA prompt you didn't initiate. Lost device or suspected phishing → tell the Founder and Compliance Officer immediately.
  • Use an up-to-date device with a screen lock. No customer data in screenshots, personal notes, messaging apps, or personal storage — ever.

3. Working with customers

  • Verify before you act. Account and money actions require an open case assigned to you. Unfreeze, recovery links, and device resets additionally require the customer's live identity verification completed within the last 30 minutes.
  • Freeze fast, unfreeze carefully. Freezing for protection is always available to authorized staff; reversing protections has the extra gates above.
  • Balance corrections are dual-control. You can request one; a different authorized person must approve it. Never approve your own.
  • Messages to customers are delivered in-app/push/email through the console — never from personal channels.
  • No tipping off. Never tell a customer they are under fraud or compliance review, and never reveal which check they failed.

4. Identity review (compliance roles)

  • The Identity review queue is the human gate for KYC applications the automated check could not clear. Approving releases the exact staged application to our banking partner; rejecting stops it. Your decision requires reviewing the trusted ID portrait, centered selfie, and the complete live-motion recording, and writing a review note (minimum 8 characters).
  • Evidence links expire after 30 minutes and exist only inside the console. Never download, copy, re-photograph, or share identity evidence. Every evidence view is audit-logged.
  • Use the Compliance signals and Linked accounts panels (devices, IPs, sign-in history, shared identity signals) to inform decisions. Shared document or tax-ID signals are strong duplicate-identity indicators; shared devices or Wi-Fi IPs can be innocent — investigate before acting.
  • Sanctions or watchlist concerns, suspected identity fraud, or anything you can't confidently decide: escalate to the Compliance Officer the same day via a compliance case.

5. Transactions review

  • The Transactions view splits Deposits (money in) and Withdrawals (money out), with Created (customer initiated) and Posted (finalized) timestamps. Auto-sync can be paused from the header so nothing refreshes under you mid-review.
  • Patterns worth escalating: rapid in/out flows, many small deposits followed by one withdrawal, mismatch between activity and stated income, shared devices/IPs across transacting accounts.

6. PA (assistant) work

  • Work only from tasks assigned to your individual Kronos identity in the console.
  • Hard blocks — escalate instead of acting: anything involving money movement, credentials, identity changes, legal authority, or unapproved spending. Purchases and payments require an owner-approved finance request first.

7. Time & pay

  • Clock in with the ticket or task reference you're working. A reference is corroborating evidence, not automatic payroll approval — overlapping time and unmatched references are flagged for human review.
  • Submit your week when complete. Payment is monthly in USD to your verified account via KronosPay's payment partner.

8. Conduct

  • Treat customers and teammates with respect; harassment or discrimination of any kind is not tolerated.
  • Confidentiality survives your engagement: customer data, internal tooling, policies, and partner relationships stay confidential permanently.
  • Unauthorized access, data selling, or deliberate audit evasion means immediate termination and, where warranted, referral to authorities.

9. Questions & reporting

  • Product/process questions → your queue lead or the Founder.
  • Security or privacy concerns → Founder + Compliance Officer, immediately, before anything else.
  • Policy documents (BSA/AML Program, Information Security Policy) live alongside this handbook; when in doubt, the stricter document governs.

Owner controls

Money, membership and provider operations. Every action is idempotent where applicable and fully audited.

Wallet & account operations
Membership & credits
Provider operations

People intake

Secure contractor onboarding — email-bound single-use invitations, masked USD payout intake, audited five-minute document access, and enforced retention redaction.

Active invitations
—
Received submissions
—
Documents to review
—
Payout deletion overdue
—
Invite a team member

The URL is bound to one email, expires automatically, and can be used once. The secret is returned only at creation — copy it then; it is never stored or listed again.

Create an invitation to reveal its one-time URL here.

Invitation ready
Copy it now. Clearing or refreshing removes it from this browser view.
App user invite

For a customer or tester who needs their own Kronos account — this creates no staff, contractor, Ops, or money-movement access. Countries marked “Enhanced review” can submit documents but require additional provider review.

Invites

No secret tokens or invitation URLs are stored in this history.

Invited personRoleStateExpiresCreated
No invitations loaded.
Submissions

Masked payout metadata only — full account and routing numbers never enter this page. Private files open through audited five-minute links in two new tabs.

ReceivedContractorRole & startUSD payout intakeDocumentsRetentionStatus
No submissions loaded.

Redact payout intake

This permanently deletes the encrypted bank payload from the onboarding record. Masked last-four audit metadata may remain under the retention policy.

No submission selected.

Calls

Voice desk — speak with customers from this console. The browser phone rings here; no separate phone app is needed.

☎ Browser phone

Offline — Turn it on once, allow microphone access, then calls ring here.

Calls waiting
—
Agents online
—
Urgent
—
Callbacks pending
—
Incoming calls

Only calls happening now appear here. Ask for the last four digits of the customer’s Kronos account number when needed.

0 waiting
CallerStartedVerificationStatus
Open Calls to load the queue.
Callbacks

Customers who asked to be called back. Connect the browser phone first, then place the call from here.

0 pending
CustomerRequestedReasonStatus
No callbacks waiting.
Voicemails

Messages left after hours or from the overflow queue. Listen, follow up, then mark handled.

CallerLeftMessage
No voicemails waiting.

Treasury

Live pools and floats, spread revenue, ops withdrawals, and manual Sol-pool redemptions.

Solana yield pool · Kamino kUSDC
loading
Earning APY — Books halted
Position marked earning · withdrawals instant
Base pool · legacy Spark
loading
Being drained — superseded by the Solana pool
Ops float gas —
MEXC stable float
loading
USDC / USDT / DAI spot funds
HiFi ops wallet
loading
Base USDC settlement wallet
Spread & Yield

FX / conversion spread revenue from the revenue ledger, plus pool yield from the live balances call.

Spread · today
—
Spread · last 7 days
—
Spread · month to date
—
Spread · all-time
—

Spread windows sum every revenue source (yield spread, trading, transfer and eSIM fees). Legacy yield-spread rows predate the sweep ledger, so they carry all-time value but show $0 swept — recent sources sweep as they settle.

Pool yield earned (Solana)
—
Pool APY
—
Venue fees pending settlement
—
Withdrawable · Kamino liquidity
—
Spread revenue by source
SourceTodayLast 7 daysMonth to dateAll-timeSwept all-time
Withdraw from Sol pool — any coin

USDC redeems straight from the Kamino pool in one transaction. Any other coin redeems USDC and routes it through ChangeNOW, delivering the requested asset on-chain to your destination. Network is only needed when the ticker is ambiguous (e.g. eth vs eth@base).

Redeems real funds from the selected pool; non-USDC coins are converted via ChangeNOW at the live rate. Sol-pool USDC pays to a base58 Solana address; base-pool USDC pays to an EVM address. You will be asked to type WITHDRAW before the request is sent.
Ops withdrawals

Recent admin-initiated treasury movements.

Ops withdrawals
CreatedSourceAssetAmountStatusDestinationRef

Analytics

First-party product analytics — onboarding funnel, engagement, and money movement over the last 30 days.

Business metrics — live

Loading…
How every number is calculated
DAU
—
14-day series
WAU
—
Unique transactors, last 7 days
Stickiness
—
DAU / WAU (weekly)
Week-2 retention
—
Transacted again in days 8–14
Signups per day

Approved customers created each day, last 30 days.

Daily active users

Unique users per day from the event rollup, last 14 days.

Onboarding funnel

Event stages over the window, ending with transacted customers from portal data.

Completed money movement

Completed USD volume per day, last 30 days. Hover a bar for that day's transaction count.

— transactions in 30 days · —

Support inbox

Live chat with customers across app, website, email and fraud channels. Replies land instantly in-app.

CreatedTypeCustomerSubjectStatusPriorityActions
Open Cases to load the queue.
Open conversations Loading…
0 selected
— conversations
Loading conversations…
Choose a conversation

Read the customer's full history, send a reply, and resolve the thread from here.

Conversation

Customer
identity
⌘/Ctrl + Enter to send

Confirm

Identity evidence

Message the customer — sends a push notification to their app and an email from Kronos Support. Use it to explain a decision or ask for clearer evidence.

Details

Customer

Conversation history