Skip to content
KeelContact sales

Trust

Where your data is, and who else can touch it.

One region, one door out, one list of companies involved. This page is the short version. The documents behind it are drafts a lawyer has not finished reading, and this page says so wherever that matters.

  • eu-central-1, Frankfurt
  • no third-country transfer
  • six companies on the list
  • no certification claimed

Residency

One region is the product, and it is also the single point of failure.

The mechanisms are the same four the home page describes. They are repeated here because this is the page a security reviewer is sent, and it should not depend on them having read the home page first.

  • It is created in one region

    Compute, databases, backups, logs, traces and build artifacts are created in eu-central-1 and nowhere else. The region is written into every infrastructure provider block with no variable that could change it.

  • It leaves through one door

    A container starts with no route out. Every hostname resolves to the egress gateway, which reads the name out of the TLS handshake and matches it against the list before forwarding a byte. An IP literal, a port other than 443 and any unlisted name are closed at the network.

  • It is encrypted with keys held here

    Data at rest is encrypted with keys in the same region. The object store refuses any write that is not encrypted and that does not name a key, and refuses every request that is not over TLS.

  • What it did is written down

    Every model call and every tool call is a step in the run trace, recorded from the traffic rather than from your logging. A refused connection is a step too, so you can see what was blocked as well as what got through.

The diagram of the boundary, and what happens when a run touches it, is on the home page.

Who else is involved

The companies that can touch anything, and what each one touches.

This list is the whole list. It is rendered from the same file as the register in our data processing documents, so the two cannot say different things.

  • Amazon Web Services EMEA SARL

    in use today

    Services
    EC2 and EBS, S3, KMS, Secrets Manager, Route 53, Systems Manager Session Manager, CloudWatch Logs and Metrics, Data Lifecycle Manager, Elastic Container Registry
    Processes
    Everything the platform stores: the platform database on the instance volume, run and trace payload objects, static site files, nightly database dumps, generated platform credentials, DNS records for platform hostnames, container logs and host metrics, and daily machine images of the whole host.
    Where
    eu-central-1, Frankfurt
    Why
    The infrastructure Keel runs on. One region, pinned in every Terraform provider block, with no variable that could change it.
  • Internet Security Research Group (Let's Encrypt)

    in use today

    Services
    ACME certificate issuance
    Processes
    The hostnames Keel terminates TLS for: the platform hostnames, the wildcard for service and site hostnames, and every custom domain a customer points at the platform. Hostnames only, never request or response content.
    Where
    United States. Certificates and the hostnames inside them are public by design and are published to Certificate Transparency logs.
    Why
    So a customer never uploads a private key. Caddy obtains a certificate for a custom domain on its first request, and only for a hostname the relay would already route.
  • Vercel Inc.

    in use today

    Services
    Static hosting for the marketing site at keelhosting.dev
    Processes
    What the two forms on this site collect, in transit only, on its way to the Keel API in Frankfurt: a waitlist email address, and a name, work email, company and message for an enterprise enquiry. The site has no database, so nothing from the forms is stored here. No platform data, no customer run data, no traces.
    Where
    Deployed to the fra1 (Frankfurt) region. Vercel Inc. is a United States company.
    Why
    Static hosting for a site that is deliberately outside the platform's trust boundary. Both forms write through the Keel API, so the enquiries themselves live on Keel's own Frankfurt host and not in a third-party database.
  • GitHub, Inc. (Microsoft)

    in use today

    Services
    Source hosting and continuous integration for Keel's own code
    Processes
    Keel's source code and, during a deploy, short-lived OIDC credentials. No customer data. The git build path, which would send a customer's repository through a build, is not configured on the host that is live today.
    Where
    United States, with build runners wherever GitHub places them.
    Why
    Where Keel itself is developed, reviewed and deployed from.
    Note
    Listed for completeness. GitHub processes Keel's code, not customer content, on the deployment that is live today.
  • Stripe Payments Europe, Limited

    in use when the deployment enables it

    Services
    Subscription billing, Checkout, the Customer Portal, Billing Meters and invoicing
    Processes
    Billing contact details, company name, billing address, EU VAT identifier and tax status as collected in Checkout, the payment instrument, and metered usage quantities keyed by an opaque Stripe customer identifier. Never a run payload, a trace or a log line.
    Where
    Ireland, under Stripe's own terms and its own subprocessor list.
    Why
    Taking payment and issuing invoices, including the reverse charge through Stripe Tax.
    Note
    Active only when the deployment runs with BILLING=stripe. Enterprise is invoiced by hand.
  • Amazon Web Services EMEA SARL (Simple Email Service)

    not in use yet

    Services
    Transactional email for organization invitations
    Processes
    The invited person's email address and the invitation text.
    Where
    eu-central-1, Frankfurt
    Why
    Telling an invited colleague that they have been added to an organization.
    Note
    The default mailer is INVITATION_MAILER=log, which sends nothing. SES is used only once that variable is switched.

We give thirty days' notice by email, to every customer with a signed data processing agreement, before a new company on this list starts processing anything. Updating this page is not notice and we do not treat it as notice.

The Fargate deployment described in infra/terraform/modules is built but not the deployment that is live. When it is used it adds ECS Fargate, RDS, SQS, EventBridge Scheduler, EFS, CodeBuild, ACM and Elastic Container Registry for customer images, all from the same provider in the same region.

Jurisdiction and access requests

Whose law the infrastructure sits under, and what happens if a government asks.

The EU Data Act asks a hosting provider to publish this, so here it is rather than in a PDF you have to request.

Jurisdiction of the infrastructure
Everything runs in Frankfurt, Germany, and is subject to German and Union law. Our infrastructure provider contracts through a Luxembourg entity, which belongs to a group whose ultimate parent is in the United States.
Transfers
There are none for your data. We process in the EU and so does every company on the list above that touches your data, so there is no third-country transfer to put a safeguard around.
If an authority outside the EU asks
We answer only where Article 48 GDPR permits it, that is, under an international agreement in force. We tell you before we respond unless we are legally forbidden to, we challenge a request that is overbroad or unlawful, we disclose the minimum, and we do not act against your written instructions.
Requests received to date
None. We publish the number here and update it when it changes.

Which rules reach us, and which do not.

  • GDPR

    Applies

    We are your processor for what you deploy, and our own controller for your account, billing and support records. The agreement, the processing record and the measures are drafted.

  • EU Data Act, switching

    Applies

    In full, since September 2025, with no exemption for a company our size. Thirty days to switch, at least thirty more to retrieve, and we charge nothing for either.

  • NIS2

    Not in scope

    Cloud providers are in the Directive's first annex, but it reaches only entities that are at least medium-sized, roughly fifty staff or ten million euro. We are far below that. If we crossed it we would be an important entity, not an essential one.

  • DORA

    Not directly regulated

    Its obligations bind financial firms, who pass requirements down by contract. A provider is regulated directly only once it is designated critical, which has a ten percent market relevance threshold. Talk to us early if you are a financial firm, because some of what DORA asks for is beyond what we can honestly promise today.

  • EU AI Act

    Not in scope

    We are not the provider, deployer, importer or distributor of your AI system. We rent you compute and record what it did. If you build a high-risk system on us, the Act lets you require a written agreement about the information and access you need, and we will sign one.

What we do not claim

The parts a certification would have papered over.

  • We hold no SOC 2 report and no ISO 27001 certificate, and we have never had an external audit or a penetration test. There is no report to send you.

  • The platform runs on one host in one availability zone today. There is no failover and no second region, and a hardware failure is an outage until we launch the most recent machine image by hand.

  • We take a database dump every night and a machine image every day, and we have never rehearsed a restore on a schedule. We publish no recovery time objective because we have not measured one.

  • We have a program that tries to break out of the sandbox in every way the design forbids. It runs nightly against the deployment we have built for scale, and not against the one that is live.

  • Your plan states a trace retention period and we now enforce it hourly: the request and response bodies of a step are deleted once they pass it, and the step keeps its timing, status and token counts. What we still do not expire is the rest of what a run leaves behind, its output archive, its checkpoints and its log chunks, so assume those are still there.

  • There is no export-everything button and no delete-my-organization button. Both are things we do by hand, for free, on request, and you should know that before you sign rather than after.

  • A host you add to your own allowlist is outside the residency guarantee. We say so where you add it, and every connection to one is still a step in the trace.

Documents

Six documents, on request, in draft.

They are written and they are honest, and a lawyer has not finished reading them. We will send you any of them today marked as a draft rather than make you wait, because you can judge a draft and you cannot judge a promise of one.

  • Data processing agreement

    Every element Article 28(3) requires, the subprocessor terms, the audit and assistance terms, deletion on termination, and an annex of the measures with the file that implements each one.

  • Technical and organisational measures

    The long version of this page, by Article 32 heading, written for the engineer on your side. It ends with a numbered list of every gap.

  • Subprocessor register

    The list above, with the jurisdiction statement and the commitment to announce a change before it takes effect.

  • Record of processing activities

    Our Article 30(2) record. You get the extract for your organization, never a version that names another customer.

  • Breach procedure

    The runbook: the clock, who does what, how we work out which customers are affected from the audit log and the traces, and the notification templates.

  • Export and exit

    Every format and endpoint you can pull your data through, the Data Act timeline, and the four things that are not self-service yet.

A person

Found something, or need something signed?

Security reports and compliance questions both go to a person, not a form. Tell us what you did, what you saw and the time in UTC. A run id and an organization id are enough for us to find it, so please do not send us anyone's personal data.

security@keelhosting.dev · info@keelhosting.dev