Security status and assurance
Keystone is not currently certified to Cyber Essentials, ISO 27001 or SOC 2. Cyber Essentials is our first targeted external assurance standard for a UK small-business supplier. Certification will only be stated here after it is awarded and current. We do not currently publish a penetration-test attestation.
Hosting and data regions
The application is deployed through Lovable Cloud and the primary application database, authentication service and object storage are provided by Supabase. The repository does not record a contracted production-region selection or a UK-only data-residency commitment, so Keystone does not make either claim. Customers requiring a specific hosting or data region should contact us before subscribing; we will confirm the live configuration and relevant supplier terms in writing.
Subprocessors
Core: Supabase (database, authentication and object storage) and Lovable (application deployment and service tooling). Optional or feature-dependent: Stripe (billing), OpenAI or Lovable AI Gateway (AI requests), Deepgram (audio transcription), GoHighLevel (customer communication integrations) and Cloudflare (domain/DNS tooling). A provider receives Customer Data only when the relevant service or feature needs it. Provider terms and regional processing may change; contact us for the current processor list before a regulated deployment.
Encryption and secrets
The public application uses HTTPS and enables HSTS on HTTPS responses. Supabase credentials, payment credentials and AI provider keys are read from server-side environment variables; they are not intentionally exposed in browser route components. At-rest encryption and key management for hosted data are supplied by the relevant infrastructure provider; Keystone does not independently operate an encryption-key-management service.
Authentication and authorisation
Users authenticate through Supabase Auth. Authenticated server functions validate the user token before processing. Access is scoped by workspace/company and role, with Supabase Row Level Security used for tenant isolation. The application has admin, installer and super-admin roles. Multifactor authentication is not currently a published mandatory control; customers needing it should obtain confirmation before relying on it.
Backups and disaster recovery
The production recovery runbook requires Supabase database backups and point-in-time recovery, private storage where possible, and restore drills into an isolated project at least quarterly. Storage restoration is not automatically guaranteed by a database restore. We do not currently publish a recovery-time objective, recovery-point objective or provider backup-retention period; those are operational items to be recorded and tested before any contractual commitment is made.
Staff and support access
The product separates customer access by role and company scope. Keystone administrative access is used for support, security, legal compliance and platform operations, and should be limited to the people and time needed for that purpose. The current product does not publish a formal just-in-time-access workflow or a staff-access recertification cadence, so customers should not infer either.
Logging and monitoring
The service records auditable application events, including operational and security-relevant actions, in an audit-log data set with workspace-scoped access controls. Server-side checks, signed URLs for protected files and security headers provide additional safeguards. We do not claim 24/7 security-operations-centre monitoring or a fixed log-retention period.
Vulnerability management
We maintain dependencies, apply security fixes and investigate reported vulnerabilities. Report a suspected vulnerability privately to the support address below; do not test production systems without written permission. We do not currently publish a service-level remediation timetable, bug-bounty programme or external vulnerability-scan attestation.
Incident notification
We will investigate suspected incidents, contain and document them, and notify affected customers without undue delay after becoming aware of a Personal Data Breach affecting their Customer Data. Customers remain responsible for their controller notifications unless law says otherwise. The Data Processing Addendum gives the contractual breach-notification term.
Deletion and retention
Customers should export data before subscription end and can request deletion through support. Keystone verifies authority and applies legal-retention requirements before actioning a request. The platform does not currently offer an automated whole-workspace deletion control or a published backup-retention schedule; those limitations are reflected in the Data Processing Addendum rather than hidden. Deleted active data may persist in isolated backups until their provider-controlled retention cycle expires.
Contact
For a current processor list, security questionnaire, deletion request or security report, contact
site@keystoneai.uk. Do not include credentials or sensitive data in an initial email.