Security & Trust · Kaltreon
A SOC2-prep document, not marketing fluff.
Everything below is the same scope we hand to AV / Tier-1 procurement teams before they sign a PO. Specific versions, specific retention windows, specific deployment topologies — and a roadmap with dates for the certifications that are not yet on the wall.
01 · Residency
Where your telemetry lives.
Data residency
/01Production tenants run in the region contracted at signing. Cross-region replication is opt-in, scoped to disaster recovery only, and excluded by default from Enterprise single-region contracts.
- US-East (Virginia)
- EU-Frankfurt (Enterprise only)
- AP-Tokyo (Enterprise only)
- On-prem (customer VPC)
- Air-gapped (offline install)
02–03 · Encryption
Encryption keys never leave our custody.
02 · In transit
/02All client and agent traffic terminates TLS 1.3 with HSTS preload, modern cipher suites only, and certificate pinning on the agent-to-platform channel. Enterprise tenants can require mutual TLS with customer-issued client certificates.
- TLS 1.3
- mTLS (Enterprise)
- HSTS preload
- X25519 + AES-256-GCM
03 · At rest
/03All persistent storage — telemetry, audit log, compliance artefacts — is encrypted at rest with AES-256. Key material is held in a managed KMS with per-tenant key isolation on Enterprise; secrets live in a managed vault and never in source.
- AES-256-GCM
- KMS-backed keys
- Per-tenant isolation
- Managed vault
04 · Deployment topology
Three deployment shapes.
Multi-tenant platform hosted in our region, patched and monitored by the Kaltreon SRE team. Best for fleets that want to onboard in under a day.
- Multi-tenant
- Region-pinned
- Kaltreon-managed
Single-tenant Kubernetes install into the customer's own cloud account or data centre. Telemetry stays inside the customer boundary; only signed update bundles cross it.
- Kubernetes
- Single-tenant
- Customer boundary
Fully disconnected install with cryptographically signed update bundles carried in by hand. For classified test floors and offline validation labs.
- Offline
- Signed bundles
- Manual update cadence
05 · Audit
Retention that survives the audit.
Audit-log retention
/04Every drift event, recalibration action, and reviewer touch is recorded in an append-only audit log. Retention scales with the subscription tier and is configurable up to seven years on Enterprise.
- Starter
- 90 days
- Pro
- 13 months
- Enterprise
- configurable · default 7 years
06 · Roadmap
What's on the wall — and when.
Compliance roadmap
/05The certifications below are scoped, scheduled, and resourced. Dates are targets and shift on evidence — once an audit lands, this section updates.
- Q4 2026 · SOC 2 Type I (target)
- H1 2027 · ISO 27001 (target)
- Q2 2027 · SOC 2 Type II (target)
One-pager
Take the procurement summary offline.
A one-page summary of the scope above, formatted for forwarding to your security team.
Generated client-side from the spec on this page. No data leaves your browser.
Talk to security