AES-256 Encryption

All sensitive data is encrypted at rest using industry-standard AES-256 and in transit via TLS 1.3.

Tenant Isolation

Strict logical separation of customer data at the database layer ensures your data is never accessible by other organizations.

Auth0 Identity

Enterprise-grade authentication with support for SAML SSO, MFA, and granular role-based access control.

PII Protection

Automated redaction of personally identifiable information in all production logs and system telemetry.

Architecture

Defense in Depth

Every request to Keystone is validated, sanitized, and isolated.

Auth0 Identity Edge
Cloudflare WAF
Keystone API Gateway
Tenant Isolation Layer
PII Sanitization Engine
Isolated RDS Clusters
Compliance

Operational Controls

Comprehensive protection across every layer of the platform.

Infrastructure

  • Hosted on AWS (US-East-1)
  • Virtual Private Cloud (VPC) isolation
  • Automated daily vulnerability scanning
  • DDoS protection via Cloudflare Network

Data Compliance

  • SOC2 Type II Observation Period
  • GDPR Data Processing Addendum
  • CCPA Privacy Compliance
  • Annual 3rd party penetration tests

Availability

  • 99.9% Uptime SLA for Enterprise
  • Multi-region database redundancy
  • Point-in-time recovery (PITR)
  • 15-minute RTO / 1-hour RPO

Resilience & Response

Our incident response team is on call 24/7. In the event of a service disruption, we provide real-time updates via our public status page and notify affected users within 60 minutes.

Security FAQ

Where is my data stored?

Customer data is stored in the AWS US-East-1 region. We use RDS Postgres with encrypted volumes and cross-region replication for disaster recovery.

How is PII handled by AI?

Our AI Runtime uses a dedicated sanitization layer that strips PII before any data is sent to large language models for matching or analysis.

Can we use our own AI instance?

Enterprise customers can deploy Keystone with isolated, private AI model instances to ensure zero data retention by third-party providers.

How often do you run security tests?

We perform automated vulnerability scans daily and conduct full third-party penetration tests on an annual basis.