Trust Centre

Keystone Site Security Pack

A factual record of the platform controls, service providers and operational commitments. This page does not claim a certification that Keystone has not obtained.

Last updated 7 August 2026

Security status and assurance

Keystone is not currently certified to Cyber Essentials, ISO 27001 or SOC 2. Cyber Essentials is our first targeted external assurance standard for a UK small-business supplier. Certification will only be stated here after it is awarded and current. We do not currently publish a penetration-test attestation.

Hosting and data regions

The application is deployed through Lovable Cloud and the primary application database, authentication service and object storage are provided by Supabase. The repository does not record a contracted production-region selection or a UK-only data-residency commitment, so Keystone does not make either claim. Customers requiring a specific hosting or data region should contact us before subscribing; we will confirm the live configuration and relevant supplier terms in writing.

Subprocessors

Core: Supabase (database, authentication and object storage) and Lovable (application deployment and service tooling). Optional or feature-dependent: Stripe (billing), OpenAI or Lovable AI Gateway (AI requests), Deepgram (audio transcription), GoHighLevel (customer communication integrations) and Cloudflare (domain/DNS tooling). A provider receives Customer Data only when the relevant service or feature needs it. Provider terms and regional processing may change; contact us for the current processor list before a regulated deployment.

Encryption and secrets

The public application uses HTTPS and enables HSTS on HTTPS responses. Supabase credentials, payment credentials and AI provider keys are read from server-side environment variables; they are not intentionally exposed in browser route components. At-rest encryption and key management for hosted data are supplied by the relevant infrastructure provider; Keystone does not independently operate an encryption-key-management service.

Authentication and authorisation

Users authenticate through Supabase Auth. Authenticated server functions validate the user token before processing. Access is scoped by workspace/company and role, with Supabase Row Level Security used for tenant isolation. The application has admin, installer and super-admin roles. Multifactor authentication is not currently a published mandatory control; customers needing it should obtain confirmation before relying on it.

Backups and disaster recovery

The production recovery runbook requires Supabase database backups and point-in-time recovery, private storage where possible, and restore drills into an isolated project at least quarterly. Storage restoration is not automatically guaranteed by a database restore. We do not currently publish a recovery-time objective, recovery-point objective or provider backup-retention period; those are operational items to be recorded and tested before any contractual commitment is made.

Staff and support access

The product separates customer access by role and company scope. Keystone administrative access is used for support, security, legal compliance and platform operations, and should be limited to the people and time needed for that purpose. The current product does not publish a formal just-in-time-access workflow or a staff-access recertification cadence, so customers should not infer either.

Logging and monitoring

The service records auditable application events, including operational and security-relevant actions, in an audit-log data set with workspace-scoped access controls. Server-side checks, signed URLs for protected files and security headers provide additional safeguards. We do not claim 24/7 security-operations-centre monitoring or a fixed log-retention period.

Vulnerability management

We maintain dependencies, apply security fixes and investigate reported vulnerabilities. Report a suspected vulnerability privately to the support address below; do not test production systems without written permission. We do not currently publish a service-level remediation timetable, bug-bounty programme or external vulnerability-scan attestation.

Incident notification

We will investigate suspected incidents, contain and document them, and notify affected customers without undue delay after becoming aware of a Personal Data Breach affecting their Customer Data. Customers remain responsible for their controller notifications unless law says otherwise. The Data Processing Addendum gives the contractual breach-notification term.

Deletion and retention

Customers should export data before subscription end and can request deletion through support. Keystone verifies authority and applies legal-retention requirements before actioning a request. The platform does not currently offer an automated whole-workspace deletion control or a published backup-retention schedule; those limitations are reflected in the Data Processing Addendum rather than hidden. Deleted active data may persist in isolated backups until their provider-controlled retention cycle expires.

Contact

For a current processor list, security questionnaire, deletion request or security report, contact site@keystoneai.uk. Do not include credentials or sensitive data in an initial email.