Skip to content
Trust & security

Security your auditors can inspect

KeyCustody is a system of record for the physical things that open real doors — so the record itself has to hold up. These are the properties that make it defensible, described plainly enough for the front desk and precisely enough for your risk team.

How it's built

Integrity isn't a setting — it's the design

Each property below is enforced by the way KeyCustody is built, not by a toggle someone can forget to switch on. The same design that protects your records is what makes them stand up to scrutiny.

Append-only by design

Custody, disclosure, and rotation events are immutable. A correction is a new, timestamped entry — the original is never overwritten or deleted, so the history can't be quietly rewritten.

Tenant isolation

Every organization's keys, people, and history are walled off from every other. Isolation is enforced in the data model itself, not left to convention.

Secrets private by default

Track the facts about a code or combination — what it opens, who's authorized, when it rotated — without storing the value. Encrypted storage of secret values is opt-in, never the default.

Role-based access

Front desk, maintenance, managers, and auditors each get exactly the visibility their job needs. Access is granted by role, and every grant is on the record.

Always-on activity log

Tamper-evident logging runs across the workspace and can't be switched off. Nothing your team does in KeyCustody goes unrecorded.

Exportable evidence

Produce a filtered, date-ranged history for any owner, examiner, or board on request — a defensible record you can hand over, not a screenshot.

Data handling

What we store — and what we don't

The safest secret is the one you never store. KeyCustody defaults to the metadata an audit actually needs and leaves the sensitive value out of the system entirely — unless you decide otherwise.

The facts, by default
For a key or code, KeyCustody records its identity, what it opens, its location and copies, its status, and the person or role that holds it — the metadata an audit actually needs.
Secret values, only if you ask
Storing the actual digits of a code or combination is opt-in and encrypted at rest. Most teams run in metadata-only mode and never store the secret at all.
A complete custody trail
Every issue, return, disclosure, and rotation is captured with its timestamp, author, and reason — the append-only trail that the rest of the record is built on.
Your data stays yours
Export your full history at any time. We don't sell customer data or use it to train third-party models. Retention and deletion terms are set out in writing during onboarding.
Access & controls

The right people, the right access

Who can see and do what is scoped by role and provable on the record — from a single front desk to a multi-branch institution under dual control.

Roles & permissions

Scope visibility and actions to a role so the right people see the right keys — and nothing more.

Clean offboarding

Retire a departing person's keys and codes in a single pass, and rotate the codes they knew — with a record of exactly what came back.

Dual control

Enterprise

Record two-person access on vaults and night drops so the control is provable, not aspirational.

SSO & SCIM

Enterprise

Connect your identity provider for single sign-on and automated user provisioning on Enterprise plans.

Why it holds up

The record can't be quietly changed

An audit trail you can edit is one no one has to trust. KeyCustody's ledgers are append-only, tenant-isolated, and always logging — so when an examiner, owner, or board asks who had access in March, the answer is already written down.

Immutable ledgers
Corrections append a new event; a version is never lost.
Tenant isolation
Your records are walled off in the data model, not by policy.
Always-on activity log
Tamper-evident, workspace-wide, and impossible to switch off.
Evidence on demand
Export a filtered, date-ranged history whenever it's asked for.
Where we stand

Straight talk on compliance

We'd rather be trusted than clever. Here's exactly where KeyCustody is on the things risk and procurement teams ask about — including what isn't finished yet.

Built to audited controls

KeyCustody is engineered around the access, integrity, and logging controls a SOC 2 examination looks for. A formal report is on our roadmap; we'll say so plainly when it's in hand.

Security review for Enterprise

Enterprise engagements include a security review — we'll work through your questionnaire, architecture questions, and data-handling terms directly with your team.

Privacy by contract

Data ownership, retention, and deletion are committed to in writing. Our Privacy Policy and Terms set the baseline; Enterprise agreements can add a DPA.

Report a security concern

Found something that looks off? We welcome responsible disclosure and will work with you on any legitimate issue — no legal threats, no runaround.

security@keycustody.io →
Questions

Security, answered

Does KeyCustody store my actual codes and combinations?
Only if you choose to. By default KeyCustody runs in metadata-only mode — it tracks what a code opens, who's authorized, and when it rotated, without storing the value. Storing the secret itself is opt-in and encrypted at rest.
Can anyone edit or delete the custody history?
No. The custody, disclosure, and rotation ledgers are append-only. A correction is recorded as a new, timestamped entry; the original event is never overwritten or removed. That's what makes the record defensible in an audit or dispute.
How is one organization's data kept separate from another's?
Tenant isolation is enforced in the data model, not by convention. Every key, person, and event belongs to exactly one organization and is walled off from every other.
Are you SOC 2 certified?
Not yet, and we won't claim otherwise. KeyCustody is built around the controls a SOC 2 audit examines, and a formal report is on our roadmap. Enterprise customers can request a security review today.
How do I report a security concern?
Email security@keycustody.io and we'll route it to the right person. We welcome responsible disclosure and will work with you on any legitimate issue.

Bring your risk team.

We'll walk your security and operations stakeholders through the data model, the controls, and exactly how the record holds up.