Google Cloud Platform
Hosted on Google Cloud Platform as independent regional deployments in the UK (London), EU (Netherlands) and US (Iowa), so customer data stays in-jurisdiction.
Security and trust
If you are assessing Klarvant as a supplier, this page is written for you. It sets out how Namespace Command is built, hosted and operated, how your data is protected, and how those controls are tested. The summary below answers the questions that open most assessments; the sections that follow give the detail behind each one.
Built on security-first principles, with enterprise-grade protection.
At a glance
| Row | Value |
|---|---|
| Hosting | Google Cloud Platform, independent regional deployments |
| Data residency | UK (London), EU (Netherlands), US (Iowa); database, backups and derived audio in-region; per-region encryption keys |
| Encryption at rest | AES-256 everywhere; dedicated per-region keys in Google Cloud KMS on databases and content stores, automated 90-day rotation |
| Encryption in transit | TLS 1.2+ (modern profile), HTTPS-only, HSTS; hybrid post-quantum key exchange (ML-KEM) on TLS 1.3 |
| Authentication | Passwordless: Google/Microsoft SSO (OIDC) or single-use email links; no stored passwords |
| Tenant isolation | PostgreSQL row-level security on all customer-data access, plus separate regional databases |
| Access to customer systems | None. No agents, no credentials; publicly observable data only |
| Independent testing | Annual external penetration test (OWASP/PTES); last completed 2025, next September 2026 |
| Availability | 99.9% target per environment, continuously measured out-of-band, monthly reports; zone-redundant application tier with live database standbys |
Klarvant Namespace Command™ is a cloud-hosted platform built on Google Cloud Platform, with security, privacy, and compliance at its core. We maintain transparent security practices and undergo regular independent assessments.
Platform architecture
Hosted on Google Cloud Platform as independent regional deployments in the UK (London), EU (Netherlands) and US (Iowa), so customer data stays in-jurisdiction.
A global HTTPS load balancer, Google Cloud Armor WAF and VPC firewalls at every layer, with OWASP Core Rule Set inspection, per-IP rate limiting and adaptive Layer-7 DDoS protection.
No agents, no API keys, no privileged access required. Assets are discovered from public sources without expanding your attack surface.
Group
Data protection and encryption
A Data Classification and Handling Policy with three levels:
Access control and authentication
Group
Secure software development
Private repositories with MFA enforcement, role-based access, and audit logging. Source-code access is restricted to authorised developers only.
Network and application security
Release and assurance
Standard releases soak in pre-production for at least 24 hours, then roll out region by region, each region approved by a named engineer, running the exact artefact that was tested. Images are promoted, never rebuilt. Emergency fixes follow a documented expedited procedure through the same per-region approval gates.
Static analysis (CodeQL) and dependency vulnerability scanning run on every change, with weekly automated dependency updates. Synthetic monitoring probes every five minutes, including negative authentication tests.
Monitoring and incident response
Group
Compliance and independent testing
Development
Architecture
Data protection
Group
Business continuity and resilience
Independent regional deployments in the UK, EU and US keep customer data in-jurisdiction. Regional customer environments are never connected to each other.
Automated daily and weekly encrypted database snapshots (7-day and 6-month retention), stored in-region to preserve data residency, with deletion protection on all database hosts and restore procedures verified by an automated weekly restore test.
A 99.9% availability target per environment, continuously measured by out-of-band synthetic monitoring with monthly reports. The application tier runs on zone-redundant managed infrastructure, and each production database maintains a live streaming standby in a second availability zone under a documented failover procedure.
The Platform Update Policy defines risk-based change categories with appropriate notification windows and rollback procedures:
Patch
Immediate, security-critical fixes
Maintenance
Minor updates, 24h notice
Minor
Feature updates, 72h notice
Major
Breaking changes, two weeks' notice
We welcome security researchers, customers, and collaborators to contact us on security matters. For vulnerability disclosures, please include detail on the issue, steps to reproduce, and any supporting materials. We typically respond within one to two working days.
Security and vulnerability disclosure
security@klarvant.com
Security documentation is available to enterprise customers on request.