keystoneDetect · Remediate · Prove

SECURITY & TRUST

Security & trust

Keystone reads your cloud control plane. That is a serious level of access, so here is exactly how it works, what we hold, and how to tell us when something is wrong.

Last updated August 2026

How Keystone connects

Keystone connects to AWS through a cross-account IAM role with an external ID, and to Azure through an app registration scoped to the subscriptions you nominate. You create the role or registration in your own tenant, and you can revoke it at any time without contacting us.

We never ask for long-lived access keys, root credentials, or console passwords. If any onboarding step ever asks you for one, it is not us.

What the access allows

  • Read-only description of resources, configuration and metadata across the accounts you connect.
  • Read of identity, policy and network configuration required to evaluate guardrails.
  • Write access only where you explicitly enable an automation, and only for the specific action that automation performs.
  • No access to the contents of your storage buckets, databases, message queues or application data.

Every automation is off by default. Enabling one is a deliberate, per-action decision and is recorded in your audit log with the actor, timestamp and resulting change.

Tenant isolation

Each customer's findings, inventory and evidence are separated by tenant, and every query is scoped by tenant identifier at the data layer rather than in application code alone. Credentials issued for your connected accounts are stored encrypted and are only retrievable by jobs running on behalf of your tenant.

Encryption and data handling

  • Traffic between your browser, our services and your cloud providers is encrypted in transit using TLS.
  • Data at rest, including connection credentials, is encrypted by the managed platforms we run on.
  • We store configuration metadata and findings, not your workloads' data.
  • Backups inherit the same encryption and access controls as the primary store.

Access inside Keystone

Access to production is limited to the people who need it to operate the service, requires multi-factor authentication, and is logged. Support engineers do not browse customer data casually; access for a support case is scoped and recorded, and we will tell you if we need to look at something specific to resolve your issue.

Retention and deletion

You can disconnect an account at any time, which stops collection immediately. On request, or on termination of your subscription, we delete your inventory, findings and evidence from live systems, with backups ageing out on their normal cycle. Tell us at security@hireken.io and we will confirm in writing when deletion is complete.

Compliance posture

Keystone is in private beta and operated by hireken.io. We do not claim any certification we have not completed. If your procurement process needs a specific attestation, a security questionnaire answered, or a copy of our current architecture and subprocessor list, ask and we will tell you plainly where we are rather than sending a badge.

Reporting a vulnerability

Email security@hireken.io with the details and, if you can, a proof of concept. We acknowledge reports within one business day and will keep you updated until it is resolved. We will not pursue legal action against researchers who report in good faith, avoid privacy violations and data destruction, and give us reasonable time to fix the issue before disclosure.