Kestrelbank Controls

Security

We hold other organisations control evidence, which concentrates risk in us. Our posture reflects that.

Data

Evidence is encrypted in transit and at rest. Tenant data is logically separated and every read is attributed to an authenticated principal. Collectors hold the narrowest credential that satisfies their read, and the permissions each requires are documented before it is enabled.

Access

Staff access to production requires hardware-backed authentication and is granted per task rather than standing. Access to customer evidence is exceptional, logged, and notified.

Assurance

We are assessed annually against ISO 27001 and SOC 2 Type II, with external penetration testing twice yearly. Summary reports are available to customers under agreement.

Disclosure

We welcome reports from researchers. Write to security@w18e.spatly.io with reproduction detail. We aim to acknowledge within two working days and keep you informed through remediation, and we do not pursue researchers acting in good faith.