Built for the most sensitive data.
Keystone is designed with a security-first architecture to protect your global talent intelligence and candidate privacy.
AES-256 Encryption
All sensitive data is encrypted at rest using industry-standard AES-256 and in transit via TLS 1.3.
Tenant Isolation
Strict logical separation of customer data at the database layer ensures your data is never accessible by other organizations.
Auth0 Identity
Enterprise-grade authentication with support for SAML SSO, MFA, and granular role-based access control.
PII Protection
Automated redaction of personally identifiable information in all production logs and system telemetry.
Defense in Depth
Every request to Keystone is validated, sanitized, and isolated.
Operational Controls
Comprehensive protection across every layer of the platform.
Infrastructure
- Hosted on AWS (US-East-1)
- Virtual Private Cloud (VPC) isolation
- Automated daily vulnerability scanning
- DDoS protection via Cloudflare Network
Data Compliance
- SOC2 Type II Observation Period
- GDPR Data Processing Addendum
- CCPA Privacy Compliance
- Annual 3rd party penetration tests
Availability
- 99.9% Uptime SLA for Enterprise
- Multi-region database redundancy
- Point-in-time recovery (PITR)
- 15-minute RTO / 1-hour RPO
Resilience & Response
Our incident response team is on call 24/7. In the event of a service disruption, we provide real-time updates via our public status page and notify affected users within 60 minutes.
Security FAQ
Where is my data stored?
Customer data is stored in the AWS US-East-1 region. We use RDS Postgres with encrypted volumes and cross-region replication for disaster recovery.
How is PII handled by AI?
Our AI Runtime uses a dedicated sanitization layer that strips PII before any data is sent to large language models for matching or analysis.
Can we use our own AI instance?
Enterprise customers can deploy Keystone with isolated, private AI model instances to ensure zero data retention by third-party providers.
How often do you run security tests?
We perform automated vulnerability scans daily and conduct full third-party penetration tests on an annual basis.