Skip to content
LegalPrincipality of Kaharagia

K-Connect

The single sign-on of the State. It holds credentials, sessions and the link between an account and a person record in the register, and it gates services it does not itself operate.

Service notice for connect.kaharagia.org. Last reviewed 12 July 2026.

This notice is supplementary. It states only what is particular to this service. The general Privacy Policy, Terms of Service, Cookies Policy and the other policies of the State apply in full, and this notice is read together with them.

Privacy SupplementGeneral Privacy Policy

Responsible Organ

K-Connect is operated under the Secretariat of State, Section I (Governance). The person record to which a K-Connect account may be linked is held by the General Register Office, a body of the Royal Chancellery, and is not part of K-Connect.

Data Specific to This Service

Beyond the account data described generically in the general Privacy Policy, K-Connect processes:

  • Credentials. Passwords are stored only as salted cryptographic hashes, and are never held in a form the State can read. Where a second factor is registered, K-Connect holds the shared secret for a time-based one-time code, or the public key of a registered passkey or security key, together with the date the factor was registered.
  • Claim data. A person who already holds a record in the register may claim it by presenting their Kaharagia identity code and the secret code issued with that record. K-Connect checks the pair against the register and, if it matches, records the link between the account and the person record. The secret code is not stored by K-Connect and is not displayed back to the user.
  • Session and access records. Session identifiers, the time and network address of each sign-in and sign-out, the browser and device reported by the client, the outcome of each attempt, and a record of which official services the account was used to reach, and when. A signed-in national can see and revoke their own active sessions.
  • Anti-abuse data. A proof-of-work challenge is used on registration and password reset, to deter automated account creation. It does not track the user across sites.

Biometrics

Where a passkey, or a device fingerprint or face unlock, is used to sign in, the biometric is checked on the user's own device and never reaches K-Connect. K-Connect receives only a cryptographic assertion that the device performed the check. K-Connect does not collect, store or compare biometric data. Biometric identity verification is a separate ePortal service, governed by the ePortal notice.

Sharing With Connected Services

When an account is used to reach an official service, that service receives only what it needs to know who is signed in: the account identifier, the name, the verified email address, the linked person record identifier where one exists, and any roles that govern access. Connected services do not receive credentials, second-factor secrets, or session history. K-Connect does not receive the substance of what a national does inside a connected service.

Retention Specific to This Service

A session record ends when the session ends or expires. Sign-in and security event logs are kept for the period needed to investigate account compromise and abuse, and may outlive the account. Credentials and second-factor registrations are held while the account exists. Closing a K-Connect account does not delete the person record held by the General Register Office; that record is governed by register law.

Terms SupplementGeneral Terms of Service

What K-Connect Is Not

K-Connect proves who you are. It decides nothing. Holding a K-Connect account is not nationality, not residence, not an appointment, and not a right of access to any service. A service reached through K-Connect may impose its own conditions, and may refuse access to an account that authenticates successfully.

Eligibility, and One Account per Person

One person may hold one K-Connect account, and an account is personal to its holder. A national who already holds a record in the register must claim that record rather than create a second identity. Creating a duplicate or parallel account, or holding an account in a name that is not your own, is a breach of these terms and may lead to the closure of every account concerned.

Account Holder Duties

The holder of an account must:

  • keep the password unique to K-Connect, and not reuse it on any other service;
  • keep the secret code issued with a register record confidential, and treat a request for it from anyone other than K-Connect itself as an attempt at fraud;
  • keep the registered email address current, since it is the route by which the account is recovered;
  • not share, lend, sell or transfer credentials or an account, whether or not any advantage is gained; and
  • report a suspected compromise promptly, so that sessions can be revoked.

Actions taken while an account is signed in are treated as the acts of the holder, unless the holder has reported a compromise, or unless the holder shows that the acts were not theirs.

Prohibited Conduct Specific to K-Connect

Beyond the conduct prohibited by the general Terms of Service, a user must not:

  • attempt to sign in to an account that is not theirs, including by guessing, by reusing leaked passwords, or by automating attempts;
  • attempt to claim a register record that is not theirs;
  • automate calls to the sign-in, registration, password reset or verification endpoints;
  • attempt to obtain the credentials, codes, tokens or secret codes of another person, whether by technical means or by deception; or
  • build or operate any service that impersonates K-Connect, or that collects K-Connect credentials.

These acts affect the integrity of every service that relies on K-Connect, and are treated as serious.

Suspension and Recovery

An account may be suspended immediately where there is reason to believe it has been compromised, or where it is being used against these terms. Suspension of K-Connect suspends access to every service reached through it. Recovery of an account requires proof of identity to a standard the State considers sufficient, and the State may refuse to restore an account where that standard cannot be met.

Closing an Account

A national may ask for their K-Connect account to be closed. Closing the account removes the means of signing in. It does not withdraw a petition, cancel an application, revoke a document already issued, or erase a register entry.