Security

Your customer data and operations
protected by design.

Encryption in transit and at rest, role-based access, immutable audit trail and GDPR compliance, not as optional add-ons, but built into the core architecture.

End-to-end encryptionGDPR · EU data residencyMFA availableAutomated backups
Security pillars

Six layers of protection built into the core.

Security is not a platform feature. It is the way the platform is built.

End-to-end encryption
All data is encrypted in transit and at rest. No data travels or is stored in plain text.
Role-based access
Each user only sees what they need to see. Granular permissions by role (operator, manager, owner) and by site.
Immutable audit trail
Every action is logged: which user, from which IP, at which site and at what time. The log cannot be edited or deleted.
GDPR compliance
Keevaris acts as data processor under the GDPR. Data processing compliant with the EU General Data Protection Regulation. DPA available on request.
Multi-factor authentication
MFA available for all users. SSO authentication available on Enterprise plans.
Backups and recovery
Automated backups included on all plans. Retention and recovery options defined by the contracted plan.
Infrastructure

Built to stay available.

Security is worthless if the system is down. This is what runs behind it.

Hosted in the European Union
Data is stored in data centres within the EU, in line with GDPR data residency requirements.
Data isolation per operator
Each account's data is logically separated. No operator can see or access another's data, whether by error or by design.
Continuous monitoring
System health is monitored continuously, with automatic alerts on any availability or performance anomaly.
Backups and recovery
Automated backups and a disaster recovery plan, so an infrastructure failure never means data loss.
GDPR

GDPR compliant for EU operators.

Keevaris acts as data processor under the GDPR. Data Processing Agreement available on request. Data hosted within the European Union.

Request DPA →
FAQ

What an IT team usually asks before signing.

Where is data hosted?×

In data centres within the European Union, in line with GDPR data residency requirements.

Do you hold ISO 27001 or SOC 2 certification?+
What happens if you detect a security incident?+
Can I request deletion of a customer's data?+
Do the external providers you use also comply with GDPR?+

Questions about security or compliance?

Tell us what you need: DPA, security questionnaire, policy access or technical review. We handle it directly with our team.