Encryption with dedicated keys
Every company has its own AWS KMS key to encrypt its secrets and data.
Security
Ketrics isolates every company across five layers, from how data is stored to how code is executed.
Every record and every file carries your company's identifier in its storage key.
Every access path, indexes included, is filtered by company.
IAM policies only allow access to your company's keys and paths.
Each operation assumes an AWS role tagged with your company. A bug in code cannot reach another company's data.
Each application's code runs in its own worker per invocation, with no system access, discarded when it finishes.
Every company has its own AWS KMS key to encrypt its secrets and data.
Two-factor authentication, SSO, at most 10 concurrent sessions per user and lockout after failed sign-in attempts.
The data agent initiates every connection outbound over HTTPS. Your network exposes no ports.
Activating elevated roles, deleting databases or accepting agreements requires two-factor confirmation.
Changes are recorded and signed, so you can review who did what and when.
Aurora PostgreSQL, DynamoDB, S3 and KMS, operated by Ketrics with database backups.
We answer security questionnaires and walk your team through the architecture.
Tell us what you want to solve and we'll show you how it would look on Ketrics.