Security

Built so your data stays yours.

People, payroll, and compliance data is the most sensitive data in your organization. We treat it that way — from the architecture through the access controls to the operational practices.

01

Encrypted by default.

Everything encrypted in transit; sensitive data encrypted at rest at the application layer. Modern algorithms, regularly reviewed.

02

Audited by design.

Every operational action recorded, timestamped, immutable. Nothing changes silently. Everything is queryable.

03

Access tightly scoped.

Role-based access enforced server-side. People see what their job requires — no more, no less.

Data protectionHow your data is stored and moved.

Encryption in transit

All traffic to and from the platform uses modern TLS. Older protocols are disabled. Certificates are issued from reputable authorities and rotated regularly.

Encryption at rest

Sensitive data — documents, credentials, and bank details — is encrypted at rest using strong, industry-standard encryption. Backups carry the same protection.

Data residency

Production data is hosted in audited cloud regions. Enterprise customers can request a specific region for compliance with local regulations.

Access controlHow access decisions are made.

Role-based access control

Permissions are scoped to roles and enforced server-side on every request. Users only see and act on what their role permits — no client-side authorization to bypass.

Two-factor authentication

Available on every plan. Configurable per organization — administrators can enforce two-factor authentication across their team. Time-based one-time passcodes via standard authenticator apps.

Session management

Sessions expire on a configurable schedule. Users can review and revoke active sessions from their account.

Single sign-on

SAML 2.0 SSO available on Enterprise plans. SCIM provisioning supported. Integrates with major identity providers.

Audit & observabilityHow we make actions accountable.

Immutable audit log

Every operational event — every rate change, leave approval, payslip release, role update — is captured with actor, timestamp, and before/after values. The log can be queried, exported, and produced for regulators.

System monitoring

Production systems are monitored continuously for availability, errors, and security signals.

Incident response

We maintain a documented incident response process. Affected customers are notified promptly when an incident materially impacts service or data.

Operational securityHow the team works.

Personnel access

We do not access your data outside support requests you authorize.

Vulnerability disclosure

Security researchers can report vulnerabilities to security@keystona.io. We acknowledge reports promptly and credit researchers when appropriate.

Compliance posture.

Where we are today, where we're going. We commit to being honest about both.

GDPR alignment

Data processing aligned with GDPR principles — purpose limitation, data minimization, user rights, subprocessor management.

In place

Encryption standards

Industry-standard encryption applied in transit, with sensitive data encrypted at rest.

In place

Disaster recovery

We back up production data and are formalizing our disaster-recovery procedures. Recovery objectives and runbooks are being documented.

In progress

Security team review or due diligence?

We're happy to walk security and compliance teams through our architecture, controls, and audit posture. Detailed documentation is available under NDA.