Compliance & trust
Security built in. Not bolted on.
Plain-language security posture for Keystone — encryption, tenant isolation, MFA for every user, rate limiting, bot protection and audit trails, on EU cloud or your own servers.
Hosting
AWS Ireland (eu-west-1) — or on-premise.
Tenant data resides in the EU by default. Each Keystone tenant runs in a logically isolated MongoDB database — cross-tenant queries are impossible at the application layer. Where company policy or retailer contracts require it, Keystone deploys as a local on-premise installation on your own infrastructure. Same product, same audit trail.
Encryption
AES-256 at rest. TLS 1.3 in transit.
- At rest — KMS-managed keys. Backups encrypted under the same key hierarchy.
- In transit — TLS 1.3 enforced. HSTS preload-eligible. No TLS 1.0/1.1.
- Field-level — Sensitive PII fields encrypted application-side before reaching MongoDB.
Access controls
MFA for every user. Not just admins.
- Multi-factor authentication — TOTP-based MFA available across all roles.
- Rate limiting — API rate limiting on all public and authenticated endpoints.
- Brute-force lockout — Failed-login throttling and IP lockout on all authentication endpoints.
- Bot protection — reCAPTCHA on public-facing forms — signup, contact and login flows.
- Role-based access — Per-tenant roles: super_admin · admin · ops_user · viewer · demo.
Compliance & standards
GDPR compliant. ISO 27001-aligned controls.
- GDPR — Compliant — internal Data Protection Lead (privacy@cloudvoro.com).
- Irish Data Protection Act 2018 — Domestic implementation of GDPR.
- EU Regulation 178/2002 — Batch model designed to evidence Art. 18 traceability end-to-end.
- ISO 27001:2022 — Security controls mapped to the Annex A framework — access management, encryption, logging, incident response.
- NIS2 — Tenant isolation, MFA and immutable audit trails give in-scope customers direct supporting evidence for their obligations.
Data protection lead
Named privacy contact.
CloudVoro operates with an internal Data Protection Lead reachable at privacy@cloudvoro.com. Our founder is a member of the Association of Data Protection Officers (ADPO) Ireland.
Vulnerability disclosure
Found a bug? security@cloudvoro.com.
Acknowledged within 2 business days. Fix or mitigation timeline within 10 business days. We credit researchers publicly with permission and provide a written acknowledgement letter.