Security your auditors can inspect
KeyCustody is a system of record for the physical things that open real doors — so the record itself has to hold up. These are the properties that make it defensible, described plainly enough for the front desk and precisely enough for your risk team.
Integrity isn't a setting — it's the design
Each property below is enforced by the way KeyCustody is built, not by a toggle someone can forget to switch on. The same design that protects your records is what makes them stand up to scrutiny.
Append-only by design
Custody, disclosure, and rotation events are immutable. A correction is a new, timestamped entry — the original is never overwritten or deleted, so the history can't be quietly rewritten.
Tenant isolation
Every organization's keys, people, and history are walled off from every other. Isolation is enforced in the data model itself, not left to convention.
Secrets private by default
Track the facts about a code or combination — what it opens, who's authorized, when it rotated — without storing the value. Encrypted storage of secret values is opt-in, never the default.
Role-based access
Front desk, maintenance, managers, and auditors each get exactly the visibility their job needs. Access is granted by role, and every grant is on the record.
Always-on activity log
Tamper-evident logging runs across the workspace and can't be switched off. Nothing your team does in KeyCustody goes unrecorded.
Exportable evidence
Produce a filtered, date-ranged history for any owner, examiner, or board on request — a defensible record you can hand over, not a screenshot.
What we store — and what we don't
The safest secret is the one you never store. KeyCustody defaults to the metadata an audit actually needs and leaves the sensitive value out of the system entirely — unless you decide otherwise.
- The facts, by default
- For a key or code, KeyCustody records its identity, what it opens, its location and copies, its status, and the person or role that holds it — the metadata an audit actually needs.
- Secret values, only if you ask
- Storing the actual digits of a code or combination is opt-in and encrypted at rest. Most teams run in metadata-only mode and never store the secret at all.
- A complete custody trail
- Every issue, return, disclosure, and rotation is captured with its timestamp, author, and reason — the append-only trail that the rest of the record is built on.
- Your data stays yours
- Export your full history at any time. We don't sell customer data or use it to train third-party models. Retention and deletion terms are set out in writing during onboarding.
The right people, the right access
Who can see and do what is scoped by role and provable on the record — from a single front desk to a multi-branch institution under dual control.
Roles & permissions
Scope visibility and actions to a role so the right people see the right keys — and nothing more.
Clean offboarding
Retire a departing person's keys and codes in a single pass, and rotate the codes they knew — with a record of exactly what came back.
Dual control
EnterpriseRecord two-person access on vaults and night drops so the control is provable, not aspirational.
SSO & SCIM
EnterpriseConnect your identity provider for single sign-on and automated user provisioning on Enterprise plans.
The record can't be quietly changed
An audit trail you can edit is one no one has to trust. KeyCustody's ledgers are append-only, tenant-isolated, and always logging — so when an examiner, owner, or board asks who had access in March, the answer is already written down.
- Immutable ledgers
- Corrections append a new event; a version is never lost.
- Tenant isolation
- Your records are walled off in the data model, not by policy.
- Always-on activity log
- Tamper-evident, workspace-wide, and impossible to switch off.
- Evidence on demand
- Export a filtered, date-ranged history whenever it's asked for.
Straight talk on compliance
We'd rather be trusted than clever. Here's exactly where KeyCustody is on the things risk and procurement teams ask about — including what isn't finished yet.
Built to audited controls
KeyCustody is engineered around the access, integrity, and logging controls a SOC 2 examination looks for. A formal report is on our roadmap; we'll say so plainly when it's in hand.
Security review for Enterprise
Enterprise engagements include a security review — we'll work through your questionnaire, architecture questions, and data-handling terms directly with your team.
Privacy by contract
Data ownership, retention, and deletion are committed to in writing. Our Privacy Policy and Terms set the baseline; Enterprise agreements can add a DPA.
Report a security concern
Found something that looks off? We welcome responsible disclosure and will work with you on any legitimate issue — no legal threats, no runaround.
Security, answered
- Does KeyCustody store my actual codes and combinations?
- Only if you choose to. By default KeyCustody runs in metadata-only mode — it tracks what a code opens, who's authorized, and when it rotated, without storing the value. Storing the secret itself is opt-in and encrypted at rest.
- Can anyone edit or delete the custody history?
- No. The custody, disclosure, and rotation ledgers are append-only. A correction is recorded as a new, timestamped entry; the original event is never overwritten or removed. That's what makes the record defensible in an audit or dispute.
- How is one organization's data kept separate from another's?
- Tenant isolation is enforced in the data model, not by convention. Every key, person, and event belongs to exactly one organization and is walled off from every other.
- Are you SOC 2 certified?
- Not yet, and we won't claim otherwise. KeyCustody is built around the controls a SOC 2 audit examines, and a formal report is on our roadmap. Enterprise customers can request a security review today.
- How do I report a security concern?
- Email security@keycustody.io and we'll route it to the right person. We welcome responsible disclosure and will work with you on any legitimate issue.
Bring your risk team.
We'll walk your security and operations stakeholders through the data model, the controls, and exactly how the record holds up.