KEPTA Enterprise — Trust Center
The open architecture answer, instead of certificate seals.
Every claim on this page is readable in code and demonstrable in the app with a single click. The threat model we took off the table is the ordinary one: the cloud itself.
The principle
Other vendors document how well they protect your data while transporting it into their datacenter. KEPTA Enterprise never transports it: an organization's brain lives in encrypted files on machines the organization controls. There is no vendor access path, so there is no vendor access to answer for.
For procurement: the strongest data argument is an architecture test — "show me the path through which a client's matter leaves your building." Ours ends at your own network card.
Encryption, layer by layer
| Layer | Mechanism |
|---|---|
| Data at rest | SQLCipher 4: AES-256 plus an HMAC-SHA512 over every page, WAL included |
| Per tenant | Every tenant brain carries its own derived key — one compromised tenant key never opens the others |
| Key custody | The master key lives in the operator's OS keychain; BYOK/KMS adapter on the roadmap |
| Transport | Console binds loopback by default; deployments sit behind your firewall or run air-gapped |
Tamper-evident audit chain
Every read and write of a tenant brain appends to a SHA-256 hash chain: line n carries the hash of line n−1. An edited, deleted or reordered entry visibly breaks the chain — and the app shows the exact row. The verify button recomputes the whole chain live and issues a seal with server timestamp and chain-tip fingerprint.
Human review for agent writes
Writes run through a per-tenant write policy: automatic, or gated by a human decision. The console shows "The AI wanted → what happened" — intent versus reality, with actor, resource and timestamp in the chain.
Point-in-time recovery
The time machine reconstructs a tenant's knowledge at any moment from the chain and restores it with a guarded restore that keeps the evidence chain intact.
§203 StGB — professional secrecy (law firms, tax advisors, physicians)
- Tenant separation: each client's brain is separated with its own key; bound agent keys see only their tenant (isolation is contract-tested — foreign access returns 403)
- Confidentiality levels: per note and per tenant, with §203-grade profiles on the roadmap
- No third-party leak: no cloud, no telemetry, no embedded third parties in the data path
GDPR
- Data subject rights: access and erasure run against local stores — no upstream processor to file requests with; deletion is provable through the chain
- Processor status: in the standard architecture we are not a processor, because we never receive your data
- Data residency: the strictest residency proof is machine ownership — your firm, your server, your country
HIPAA / BAA — our position
We do not sell a Business Associate Agreement wrapper, because in standard deployment we are not a business associate: no protected health information is ever handed to us — it never leaves your building. Organizations whose checklists require a BAA get the same answer as for SOC 2: the architecture makes the wrapper unnecessary; we deliver the architecture proof instead. Managed options on request, under separate agreement.
Certificates (SOC 2 / ISO 27001)
Certificates attest the processes of a cloud operator. Our answer is locality dominance — we run nothing that would need attestation. For procurement that requires paper: a SOC 2 readiness checklist is available on request, and the technical controls (access, encryption, audit, integrity) are built and tested in the product.
Provability — the part you can check yourself
- In the app: audit verify with seal, human review, time machine — demonstrable live, in front of you
- In code: the private enterprise repository — 746 tests in 61 files, measured 07.10.2026
- Manipulation demo: on request we show how tampering visibly breaks the chain — the opposite of security through obscurity