06 / Data & Security

Where data lives, who reaches it.

Keystone is read-only infrastructure. It reads positions, computes risk and produces evidence-backed reports. It never holds assets, keys or trading permissions. The controls below describe where data resides and how access is governed.

Data residency

All data processing occurs within the European Union.

A single encrypted EU datastore holds all application data. No third-party object storage.

Controls
Data residency
All data is processed and stored within the European Union, on established cloud infrastructure.
Read-only connectivity
Venue and custodian connections use read-only API credentials. Keystone never requests withdrawal, transfer, or trading permissions.
Encryption
Encrypted in transit (TLS) and at rest (AES-256), across compute and storage.
Credential handling
Connection credentials are encrypted at rest and held in a dedicated secrets vault, never in source code.
Access control
Role-based access: administrator, viewer, and auditor roles, over authenticated sessions.
Infrastructure security
Administrative access is protected with two-factor authentication; deployments use federated identity with no long-lived keys.
Audit & evidence
Risk-state transitions are recorded in an append-only audit trail, with evidence bundles attached to report outputs.
Data footprint
All application data resides in a single encrypted EU datastore. No third-party object storage.
Access model

Access is role-based, over authenticated sessions. Three roles are defined:

Administrator
Manages configuration and access.
Viewer
Reads risk state and reports.
Auditor
Reviews the audit trail and evidence.
Read-only posture
Read-onlyKeystone observes and reports. It does not place, modify or route orders.
No custodyIt never holds assets, keys or client funds. Positions are read, never controlled.
No trading permissionsVenue and custodian credentials are read-only. No withdrawal, transfer or trading scope is requested.
Diligence

A one-page security overview is available to forward to security and operational-diligence teams. Further detail is available to institutional counterparties under an executed agreement.