Skip to main content
    Security

    Security at Keypra

    This page restates, in plain language, the security commitments already written into our Data Processing Agreement and Privacy Policy — where your data lives, who can reach it, how the email channel is handled, and what happens when something goes wrong. Nothing here adds to or narrows those documents; where wording differs, the contract governs.

    Security contact: security@keypra.com · machine-readable: /.well-known/security.txt

    Where your data lives

    DPA §5
    • The primary database runs in the EU (Frankfurt region) with our infrastructure provider.
    • All customer personal data is encrypted at rest with AES-256, managed by that provider. Application-level customer-managed keys (CMK) are available to regulated buyers on request under a separate Order Form.
    • All connections are protected with TLS 1.3 in transit.
    • Row-level security is enabled on every table, so records are reachable only through the access rules attached to them.

    Access control

    DPA §4 / §5
    • Access is role-based (organisation admin, manager, member) and granted on a least-privilege basis.
    • Personnel authorised to process customer personal data are bound by confidentiality obligations.
    • Staff do not read customer content as a matter of routine. Privileged, rule-bypassing access is reserved for trusted server processes and support work you have asked for.
    • Sign-in supports multi-factor and Google Workspace single sign-on today; SAML 2.0 / OIDC are available under a separate Order Form.
    • Material actions are written to an audit trail with actor, timestamp and action type.

    Keypra by Email

    DPA §5 — email channel
    • Inbound mail is accepted only from our receiving provider, over a signed webhook whose signature is verified before any content is parsed.
    • Mail reaching Keypra is protected by TLS where the sending mail server supports it. E-mail is not an end-to-end confidential medium and we cannot guarantee it.
    • Please do not send special-category, privileged or professional-secrecy material through the email channel.
    • Generic role addresses (info@, support@ and similar) are refused both as senders and as invited participants. Per-sender rate limits and loop protection apply.
    • Stored message bodies and archived replies are reachable only by trusted server processes — no browser-side role can read them — and are hard-deleted by a scheduled purge at the end of their fixed retention window.
    • A colleague you place in CC receives their own consent request and is not enrolled until they confirm.
    • Concierge replies carry no open or click tracking.

    Keys you bring yourself (BYOK)

    DPA §5
    • Provider keys you supply are encrypted with AES-256-GCM authenticated encryption.
    • The master key lives in an isolated server-side secret store and is never written to the database.
    • Every key operation is recorded in an immutable audit trail, and you can rotate or remove a key at any time.
    • FIPS 140-2 validated environments are available on request.

    Resilience and vulnerability management

    DPA §5
    • High-availability infrastructure in EU-central-1, with a recovery time objective under 15 minutes and a recovery point objective under 1 minute.
    • Continuous automated dependency and platform scanning, plus annual penetration testing through our platform provider.
    • Our infrastructure provider holds SOC 2 Type II and ISO 27001; reports are available on request. Keypra itself does not currently claim its own certification.

    Incident response and breach notification

    DPA §4.6 / Art. 33 GDPR
    • We notify affected customers within 72 hours of becoming aware of a personal data breach affecting their data.
    • Organisation admins are notified by e-mail and with an in-product banner.
    • Notification covers what happened, which categories of data were involved, what we have done, and what you should do.
    • Supervisory-authority notification duties are handled in line with the DPA and our internal runbook.

    Reporting a vulnerability

    Coordinated disclosure

    Report anything you find to security@keypra.com. We acknowledge reports within 3 business days, give you an assessment within 10 business days, and keep you updated until the issue is closed. We do not run a paid bounty programme, and we are happy to credit you when a fix ships.

    Please do

    • Write to security@keypra.com with enough detail for us to reproduce the issue.
    • Give us a reasonable window to fix the issue before publishing anything about it.
    • Test only against accounts and data you own.

    Please don't

    • Do not access, modify or retain other people's data.
    • No denial-of-service, spam, social engineering or physical intrusion.
    • Do not run automated scanning at a volume that degrades the service for others.

    Safe harbour. If you research in good faith, stay within the boundaries above, and report promptly, we will treat your work as authorised, will not pursue legal action, and will work with you on a fix.

    Contract-grade detail

    Security incidents and vulnerability reports: security@keypra.com. Privacy and DPO matters: privacy@keypra.com. Contracts and enterprise security reviews: enterprise@keypra.com.