Verified controls, stated plainly

Security, stated in the words a buyer can check.

Where your data lives, who can reach it, what we log, and where we stand on compliance. Everything here describes production today; anything not yet true is marked as under verification or on the roadmap.

AES-256Encryption at rest, Google-managed keys
TLS 1.3Encryption in transit, TLS 1.2 fallback
europe-west1Belgium. Database, chat, files and backups
Per-tenantIsolation on every request, and again in the database
Data residency

Stored and processed in europe-west1, Belgium.

Your workspace database (Cloud SQL, PostgreSQL), the Firestore database that holds chat and direct messages, Firebase Storage uploads, and automated database backups all run in Google Cloud's europe-west1 region. Primary customer data is not replicated to other regions. AI features, translation and moderation call Google's EU regional endpoints.

Your peopleBrowser and mobile. Email and password on every plan; Google or Microsoft SSO on Command and HQ.
Kayden ConnectEvery request is authorised against the caller's workspace and role. The workspace identifier comes from the verified session, never from the browser.
europe-west1, BelgiumWorkspace database, chat, file storage and automated backups. Row-level security in Postgres partitions data by workspace.EU

Two qualifications we would rather state than leave you to discover. The location of the Firebase Authentication directory, which holds account identifiers and sign-in metadata but not workspace content, is being confirmed and is not asserted here. And a small number of operational sub-processors (transactional email, payments, video hosting, bot protection, marketing analytics) operate from the United States or globally; they are listed below with the data each one touches.

Controls in production

What protects your data today.

Encryption

All traffic between your browser and Kayden Connect is encrypted with TLS 1.3 (TLS 1.2 fallback for older clients), with HTTP Strict Transport Security enforced. All customer data is encrypted at rest with AES-256, the default for Cloud SQL, Firebase Storage and Firestore, with keys managed by Google. Backups inherit the same encryption.

Tenant isolation

Data is partitioned by workspace on every query. The workspace identifier is bound to the user's session at sign-in and cannot be supplied or changed by the client. Tenant-scoped policies run server-side, and row-level security in Postgres enforces the same boundary a second time inside the database.

Roles and access

Four roles inside a workspace: Super Admin (full control), Comms Admin (content, announcements and workspace-wide communication), Space Admin (moderates one Space) and Employee (posts and reacts where permitted). Administrators can revoke every active session for a person at any time. Kayden Connect staff do not access workspace content in normal operations; production access is gated, logged and limited to a specific support request or incident.

Authentication

Firebase Authentication with email and password, Google SSO and Microsoft SSO. Multi-factor authentication comes from your identity provider when SSO is used, and from a TOTP authenticator app for email and password accounts, enrolled by each member in Settings. Password length and complexity minimums and breached-password protection are enforced. Session cookies are HttpOnly and SameSite. Organisation-wide enforced MFA, SAML 2.0 and SCIM are on the roadmap for HQ and are not available today.

Audit logging (HQ)

An audit event is recorded for security-relevant actions: sign-ins, sign-in attempts refused by workspace policy, session revocation, password changes, two-factor enrolment, invitations, deactivations and deletions, content publication and deletion, billing and plan changes, moderation decisions and administrative configuration changes, each with actor, action, resource, timestamp and source IP. In-app viewing and CSV export are on HQ. Not recorded today: sign-outs, Space permission changes, and API-key issuance. Write protections at the database level are under technical verification and entries are not cryptographically tamper-evident; we say so rather than imply otherwise.

Incident response

A written procedure covers detection, triage, containment, eradication, recovery and review. An on-call engineer is alerted by Google Cloud Monitoring on availability and database thresholds; security-specific detections are being provisioned. Where GDPR applies we notify affected administrators of a personal-data breach without undue delay and within the 72 hours Article 33 requires. Confirmed incidents are written up on the status page.

Sub-processors

Who else touches data, and where.

The providers we rely on to run the service, the purpose of each, and the region it operates from. The full register carries the transfer mechanism for each provider outside the EEA once that review is complete.

ProviderPurposeRegion
Google Cloud Platform / FirebaseAuthentication, hosting, primary database, file storageeurope-west1 (Belgium)
Google Vertex AIAI polish, Co-Pilot, quiz generationeurope-west1, enforced in code
Google Cloud TranslationOn-demand translation of posts and commentsEU regional endpoint
Google Cloud Natural Language and VisionAutomated text and image moderationEU regional endpoints
SentryApplication error and performance monitoringEU (Germany) ingest
StripeSubscription billing, Stripe Tax, payment tokenisationEU / United States
ResendTransactional email (verification, billing, security)United States
MuxVideo hosting, encoding and streamingUnited States
CloudflareCDN and bot protection on public formsGlobal edge / United States
Loops, Google Analytics, LinkedIn Insight TagMarketing email and measurement, consent-based, marketing site onlyUnited States / global
Compliance

Where we stand, without dressing it up.

Our engineering practice is informed by the SOC 2 Common Criteria. We hold no certification and we do not claim compliance with any regime. This table is the current position; the date at the bottom of the page is when it was last checked.

RegimeStatus
SOC 2No examination completed and no report. Not currently in scope.
ISO 27001Not certified. Not currently in scope.
GDPR (EU and UK)Data hosted in the EU by default; sub-processor transfer mechanisms under review. No formal legal review completed and no compliance claim made. A data processing agreement is available at /legal/dpa.
POPIA (South Africa)No formal legal review completed. We do not claim compliance.
CCPA / CPRA (California)No formal legal review completed. We do not claim compliance.
HIPAAWe do not sign Business Associate Agreements. Kayden Connect is not intended for protected health information.
Vulnerability disclosure

Found something? Tell us first.

Email legal@kaydenconnect.com with the subject "Security disclosure": a description of the issue and how to reproduce it, the URL or component affected, any proof-of-concept material, and your name or handle if you want to be credited.

We acknowledge every reportKayden Connect is a small team and does not commit to a fixed window; we reply as quickly as we can and keep you informed while we investigate.
Good-faith research is safeNo legal action against researchers who follow this policy, avoid privacy violations and disruption, and give us a reasonable chance to fix the issue before disclosure.
Please do notRun automated scanners or denial-of-service tests, attempt social engineering or physical intrusion, or test against accounts you do not own.

Last reviewed 2 September 2026. Related: Privacy Policy · Data Processing Agreement · Sub-processor register · Service status.

Need the control evidence for a vendor review?

Ask. We will send what exists and say plainly what does not.