Where your data lives, who can reach it, what we log, and where we stand on compliance. Everything here describes production today; anything not yet true is marked as under verification or on the roadmap.
AES-256Encryption at rest, Google-managed keys
TLS 1.3Encryption in transit, TLS 1.2 fallback
europe-west1Belgium. Database, chat, files and backups
Per-tenantIsolation on every request, and again in the database
Data residency
Stored and processed in europe-west1, Belgium.
Your workspace database (Cloud SQL, PostgreSQL), the Firestore database that holds chat and direct messages, Firebase Storage uploads, and automated database backups all run in Google Cloud's europe-west1 region. Primary customer data is not replicated to other regions. AI features, translation and moderation call Google's EU regional endpoints.
Your peopleBrowser and mobile. Email and password on every plan; Google or Microsoft SSO on Command and HQ.
Kayden ConnectEvery request is authorised against the caller's workspace and role. The workspace identifier comes from the verified session, never from the browser.
europe-west1, BelgiumWorkspace database, chat, file storage and automated backups. Row-level security in Postgres partitions data by workspace.EU
Two qualifications we would rather state than leave you to discover. The location of the Firebase Authentication directory, which holds account identifiers and sign-in metadata but not workspace content, is being confirmed and is not asserted here. And a small number of operational sub-processors (transactional email, payments, video hosting, bot protection, marketing analytics) operate from the United States or globally; they are listed below with the data each one touches.
Controls in production
What protects your data today.
Encryption
All traffic between your browser and Kayden Connect is encrypted with TLS 1.3 (TLS 1.2 fallback for older clients), with HTTP Strict Transport Security enforced. All customer data is encrypted at rest with AES-256, the default for Cloud SQL, Firebase Storage and Firestore, with keys managed by Google. Backups inherit the same encryption.
Tenant isolation
Data is partitioned by workspace on every query. The workspace identifier is bound to the user's session at sign-in and cannot be supplied or changed by the client. Tenant-scoped policies run server-side, and row-level security in Postgres enforces the same boundary a second time inside the database.
Roles and access
Four roles inside a workspace: Super Admin (full control), Comms Admin (content, announcements and workspace-wide communication), Space Admin (moderates one Space) and Employee (posts and reacts where permitted). Administrators can revoke every active session for a person at any time. Kayden Connect staff do not access workspace content in normal operations; production access is gated, logged and limited to a specific support request or incident.
Authentication
Firebase Authentication with email and password, Google SSO and Microsoft SSO. Multi-factor authentication comes from your identity provider when SSO is used, and from a TOTP authenticator app for email and password accounts, enrolled by each member in Settings. Password length and complexity minimums and breached-password protection are enforced. Session cookies are HttpOnly and SameSite. Organisation-wide enforced MFA, SAML 2.0 and SCIM are on the roadmap for HQ and are not available today.
Audit logging (HQ)
An audit event is recorded for security-relevant actions: sign-ins, sign-in attempts refused by workspace policy, session revocation, password changes, two-factor enrolment, invitations, deactivations and deletions, content publication and deletion, billing and plan changes, moderation decisions and administrative configuration changes, each with actor, action, resource, timestamp and source IP. In-app viewing and CSV export are on HQ. Not recorded today: sign-outs, Space permission changes, and API-key issuance. Write protections at the database level are under technical verification and entries are not cryptographically tamper-evident; we say so rather than imply otherwise.
Incident response
A written procedure covers detection, triage, containment, eradication, recovery and review. An on-call engineer is alerted by Google Cloud Monitoring on availability and database thresholds; security-specific detections are being provisioned. Where GDPR applies we notify affected administrators of a personal-data breach without undue delay and within the 72 hours Article 33 requires. Confirmed incidents are written up on the status page.
Sub-processors
Who else touches data, and where.
The providers we rely on to run the service, the purpose of each, and the region it operates from. The full register carries the transfer mechanism for each provider outside the EEA once that review is complete.
Marketing email and measurement, consent-based, marketing site only
United States / global
Compliance
Where we stand, without dressing it up.
Our engineering practice is informed by the SOC 2 Common Criteria. We hold no certification and we do not claim compliance with any regime. This table is the current position; the date at the bottom of the page is when it was last checked.
Regime
Status
SOC 2
No examination completed and no report. Not currently in scope.
ISO 27001
Not certified. Not currently in scope.
GDPR (EU and UK)
Data hosted in the EU by default; sub-processor transfer mechanisms under review. No formal legal review completed and no compliance claim made. A data processing agreement is available at /legal/dpa.
POPIA (South Africa)
No formal legal review completed. We do not claim compliance.
CCPA / CPRA (California)
No formal legal review completed. We do not claim compliance.
HIPAA
We do not sign Business Associate Agreements. Kayden Connect is not intended for protected health information.
Vulnerability disclosure
Found something? Tell us first.
Email legal@kaydenconnect.com with the subject "Security disclosure": a description of the issue and how to reproduce it, the URL or component affected, any proof-of-concept material, and your name or handle if you want to be credited.
We acknowledge every reportKayden Connect is a small team and does not commit to a fixed window; we reply as quickly as we can and keep you informed while we investigate.
Good-faith research is safeNo legal action against researchers who follow this policy, avoid privacy violations and disruption, and give us a reasonable chance to fix the issue before disclosure.
Please do notRun automated scanners or denial-of-service tests, attempt social engineering or physical intrusion, or test against accounts you do not own.