Security
Resident data is a responsibility.
Keystone holds the daily life of a building: who lives where, what they pay, when their packages arrive. We treat that with the seriousness it deserves, and we describe our security honestly.
Encryption everywhere
All traffic is encrypted in transit with TLS 1.2+. Data is encrypted at rest with AES-256 on our infrastructure provider.
Role-based access
Residents, front desk, managers, and vendors each see exactly their scope. It’s enforced in the application and again at the database layer.
Row-level security
Tenant isolation is enforced at the database row level. A query for one building cannot return another building’s data.
Vendor scoping
Vendors access only their assigned work orders in their assigned buildings, with resident contact details hidden unless you allow them.
Certified infrastructure
Keystone runs on infrastructure that is SOC 2 Type II certified and independently audited, with continuous backups and point-in-time recovery.
Payments never touch us
Card and bank details are handled entirely by our PCI DSS Level 1 certified payment processor. Keystone never stores payment credentials.
A note on certifications. Keystone is built on SOC 2 Type II certified infrastructure. Keystone itself has not yet completed an independent SOC 2 audit. We are early, and we won't claim otherwise. Our own audit is on the roadmap as the platform scales, and we're happy to walk through our architecture and practices in detail on a call.
Security questions or disclosures: security@keystonepm.app
See it running a real building.
Fifteen minutes. We'll walk you through it live.