Security & Trust · Kaltreon

A SOC2-prep document, not marketing fluff.

Everything below is the same scope we hand to AV / Tier-1 procurement teams before they sign a PO. Specific versions, specific retention windows, specific deployment topologies — and a roadmap with dates for the certifications that are not yet on the wall.

01 · Residency

Where your telemetry lives.

Data residency

/01
Regional by default, sovereign on Enterprise.

Production tenants run in the region contracted at signing. Cross-region replication is opt-in, scoped to disaster recovery only, and excluded by default from Enterprise single-region contracts.

  • US-East (Virginia)
  • EU-Frankfurt (Enterprise only)
  • AP-Tokyo (Enterprise only)
  • On-prem (customer VPC)
  • Air-gapped (offline install)

02–03 · Encryption

Encryption keys never leave our custody.

02 · In transit

/02
TLS 1.3, mTLS on Enterprise.

All client and agent traffic terminates TLS 1.3 with HSTS preload, modern cipher suites only, and certificate pinning on the agent-to-platform channel. Enterprise tenants can require mutual TLS with customer-issued client certificates.

  • TLS 1.3
  • mTLS (Enterprise)
  • HSTS preload
  • X25519 + AES-256-GCM

03 · At rest

/03
AES-256, KMS-backed, per-tenant isolated.

All persistent storage — telemetry, audit log, compliance artefacts — is encrypted at rest with AES-256. Key material is held in a managed KMS with per-tenant key isolation on Enterprise; secrets live in a managed vault and never in source.

  • AES-256-GCM
  • KMS-backed keys
  • Per-tenant isolation
  • Managed vault

04 · Deployment topology

Three deployment shapes.

Cloud
Managed SaaS

Multi-tenant platform hosted in our region, patched and monitored by the Kaltreon SRE team. Best for fleets that want to onboard in under a day.

  • Multi-tenant
  • Region-pinned
  • Kaltreon-managed
On-prem
Customer VPC

Single-tenant Kubernetes install into the customer's own cloud account or data centre. Telemetry stays inside the customer boundary; only signed update bundles cross it.

  • Kubernetes
  • Single-tenant
  • Customer boundary
Air-gapped
Offline install

Fully disconnected install with cryptographically signed update bundles carried in by hand. For classified test floors and offline validation labs.

  • Offline
  • Signed bundles
  • Manual update cadence

05 · Audit

Retention that survives the audit.

Audit-log retention

/04
Tiered retention, configurable on Enterprise.

Every drift event, recalibration action, and reviewer touch is recorded in an append-only audit log. Retention scales with the subscription tier and is configurable up to seven years on Enterprise.

Starter
90 days
Pro
13 months
Enterprise
configurable · default 7 years

06 · Roadmap

What's on the wall — and when.

Compliance roadmap

/05
Targets, not claims — until they ship.

The certifications below are scoped, scheduled, and resourced. Dates are targets and shift on evidence — once an audit lands, this section updates.

  • Q4 2026 · SOC 2 Type I (target)
  • H1 2027 · ISO 27001 (target)
  • Q2 2027 · SOC 2 Type II (target)

One-pager

Take the procurement summary offline.

A one-page summary of the scope above, formatted for forwarding to your security team.

Generated client-side from the spec on this page. No data leaves your browser.

Talk to security

Have a CAIQ / SIG-Lite questionnaire? We'll fill it in.