Systems operational
Security & Trust
How Custodyn protects your data, your agents, and your customers. Built for enterprise from day one.
All systems operational
Platform · API · Dashboard · Gateway
99.9% uptime SLA
Security
Encryption at rest & in transit
All data encrypted with AES-256 at rest. All API traffic uses TLS 1.3. API keys are hashed — never stored in plaintext.
API key security
Scoped API keys per agent. Keys can be rotated instantly. Separate keys for team members with role-based access control.
Zero-trust architecture
Every request authenticated and authorized independently. No implicit trust between components. Multi-tenant isolation enforced at database level.
Tamper-proof audit logs
Every agent action logged with timestamp, outcome, and policy match. Audit logs are append-only and cannot be modified after creation.
Role-based access control
4 role tiers: Owner, Admin, Operator, Viewer. Fine-grained permissions per role. Team members can be restricted to specific functions.
Kill switch
Instantly pause all agents with a single click. Emergency stop for your entire AI fleet. Resumes instantly when ready.
Compliance Readiness
Controls built
SOC 2 Type II
All technical controls in place. Formal audit planned once we reach scale.
Controls built
GDPR
Data minimization, access controls, audit trails, and deletion on request.
HIPAA-ready
HIPAA
Technical safeguards for PHI handling — access control, audit logging, tamper-evidence, approval gates.*
* HIPAA-ready means Custodyn provides the technical controls to support your HIPAA compliance. Custodyn is not a covered entity. Consult your compliance team for formal certification.
Data Practices
| What | How long | Where | Shared |
| Agent action logs | 90 days (configurable) | Your region | Never |
| API keys | Until rotated | Encrypted at rest | Never |
| Policy rules | Until deleted | Your account only | Never |
| Approval decisions | 90 days | Your account only | Never |
| Billing information | Per retention law | Razorpay (PCI-DSS) | Payment processor only |
How Custodyn helps you achieve SOC 2
✓
CC6.1 — Logical access controls
Role-based access control with 4 permission tiers. API key scoping per agent. Team member permissions enforced at every endpoint.
✓
CC6.6 — External communication controls
All agent external calls (payments, emails, API calls) intercepted and policy-checked before execution. Blocked actions logged with reason.
✓
CC7.2 — System monitoring
Real-time monitoring of all agent actions. Anomaly detection via reputation scoring. Alerts for unusual activity patterns.
✓
CC8.1 — Change management
All policy changes logged in activity trail. Two-person approval available for critical actions. Policy versioning with rollback.
✓
CC9.2 — Vendor risk management
Track which external services each agent accesses. Block or require approval for unapproved third-party calls.
Responsible Disclosure
Security vulnerability reporting
Found a security issue? We take all reports seriously. Contact us at security@custodyn.app. We aim to respond within 24 hours and patch critical issues within 72 hours. We do not pursue legal action against good-faith security researchers.