Systems operational
Security & Trust
How Custodyn protects your data, your agents, and your customers. Built for enterprise from day one.
All systems operational
Platform · API · Dashboard · Gateway
99.9% uptime SLA
Security
Encryption at rest & in transit
All data encrypted with AES-256 at rest. All API traffic uses TLS 1.3. API keys are hashed — never stored in plaintext.
API key security
Scoped API keys per agent. Keys can be rotated instantly. Separate keys for team members with role-based access control.
Zero-trust architecture
Every request authenticated and authorized independently. No implicit trust between components. Multi-tenant isolation enforced at database level.
Tamper-proof audit logs
Every agent action logged with timestamp, outcome, and policy match. Audit logs are append-only and cannot be modified after creation.
Role-based access control
4 role tiers: Owner, Admin, Operator, Viewer. Fine-grained permissions per role. Team members can be restricted to specific functions.
Kill switch
Instantly pause all agents with a single click. Emergency stop for your entire AI fleet. Resumes instantly when ready.
Compliance Readiness
Controls built
SOC 2 Type II
All technical controls in place. Formal audit planned once we reach scale.
Controls built
GDPR
Data minimization, access controls, audit trails, and deletion on request.
HIPAA-ready
HIPAA
Technical safeguards for PHI handling — access control, audit logging, tamper-evidence, approval gates.*
* HIPAA-ready means Custodyn provides the technical controls to support your HIPAA compliance. Custodyn is not a covered entity. Consult your compliance team for formal certification.
Data Practices
WhatHow longWhereShared
Agent action logs90 days (configurable)Your regionNever
API keysUntil rotatedEncrypted at restNever
Policy rulesUntil deletedYour account onlyNever
Approval decisions90 daysYour account onlyNever
Billing informationPer retention lawRazorpay (PCI-DSS)Payment processor only
How Custodyn helps you achieve SOC 2
CC6.1 — Logical access controls
Role-based access control with 4 permission tiers. API key scoping per agent. Team member permissions enforced at every endpoint.
CC6.6 — External communication controls
All agent external calls (payments, emails, API calls) intercepted and policy-checked before execution. Blocked actions logged with reason.
CC7.2 — System monitoring
Real-time monitoring of all agent actions. Anomaly detection via reputation scoring. Alerts for unusual activity patterns.
CC8.1 — Change management
All policy changes logged in activity trail. Two-person approval available for critical actions. Policy versioning with rollback.
CC9.2 — Vendor risk management
Track which external services each agent accesses. Block or require approval for unapproved third-party calls.
Responsible Disclosure
Security vulnerability reporting
Found a security issue? We take all reports seriously. Contact us at security@custodyn.app. We aim to respond within 24 hours and patch critical issues within 72 hours. We do not pursue legal action against good-faith security researchers.