Security

Security designed in from the ground up

Ketrics isolates every company across five layers, from how data is stored to how code is executed.

Five layers of isolation

  1. 01

    Data

    Every record and every file carries your company's identifier in its storage key.

  2. 02

    Queries

    Every access path, indexes included, is filtered by company.

  3. 03

    AWS policies

    IAM policies only allow access to your company's keys and paths.

  4. 04

    Per-company credentials

    Each operation assumes an AWS role tagged with your company. A bug in code cannot reach another company's data.

  5. 05

    Isolated execution

    Each application's code runs in its own worker per invocation, with no system access, discarded when it finishes.

And also

Encryption with dedicated keys

Every company has its own AWS KMS key to encrypt its secrets and data.

Protected identities

Two-factor authentication, SSO, at most 10 concurrent sessions per user and lockout after failed sign-in attempts.

On-premise data, no open ports

The data agent initiates every connection outbound over HTTPS. Your network exposes no ports.

Sensitive actions confirmed

Activating elevated roles, deleting databases or accepting agreements requires two-factor confirmation.

Signed audit trail

Changes are recorded and signed, so you can review who did what and when.

Managed AWS infrastructure

Aurora PostgreSQL, DynamoDB, S3 and KMS, operated by Ketrics with database backups.

Does your IT team have questions?

We answer security questionnaires and walk your team through the architecture.

Talk to us

Turn your next process into an application

Tell us what you want to solve and we'll show you how it would look on Ketrics.