Security and trust

Security & Trust Centre.

Built on security-first principles, with enterprise-grade protection.

Klarvant Namespace Command™ is a cloud-hosted platform built on Google Cloud Platform, with security, privacy, and compliance at its core. We maintain transparent security practices and undergo regular independent assessments.

Platform architecture

Enterprise-grade infrastructure, global resilience.

Google Cloud Platform

Hosted on GCP with multi-region deployment (US, Europe) for high availability and data-residency requirements.

Defence in depth

Layered security with a global HTTPS load balancer, Cloud Armor WAF, and VPC firewalls protecting every layer.

Zero-integration design

No agents, no API keys, no privileged access required. Assets are discovered from public sources without expanding your attack surface.

Data protection and encryption

Encrypted at rest and in transit.

Encryption at rest

  • AES-256 encryption for all data stored on GCP (databases, logs, backups).
  • Google Cloud KMS for key management, with automated annual rotation.
  • Immutable backups with encryption and secure-deletion capabilities.
  • HSM-backed key storage, so keys are never exposed in plaintext.

Encryption in transit

  • TLS 1.2+ enforced via GCP SSL policy for all external connections.
  • HTTPS-only access through the global load balancer with automatic TLS termination.
  • Internal encryption for traffic between Google Cloud services.
  • Email over TLS for automated notifications.

Data classification and handling

A Data Classification and Handling Policy with three levels:

  • Public: information intended for public distribution.
  • Internal: business information for internal use only.
  • Confidential: sensitive data requiring strict protection controls.

Data lifecycle management

  • Production data isolation: production data is never replicated to non-production environments.
  • Test-data sanitisation: only synthetic or anonymised data is used for development and testing.
  • Secure deletion: cryptographic erasure (NIST 800-88 aligned) for decommissioned storage.

Access control and authentication

Least-privilege access, full audit trails.

Authentication and identity

  • Firebase Authentication with SSO/SAML integration for enterprise customers.
  • Multi-factor authentication (MFA) enforced for all admin and engineering access.
  • OTP/SSO only: no local passwords stored or managed.
  • Adaptive lockout and risk-based login challenges via Google/SSO.
  • Session management: 30-minute token refresh, 60-minute expiration.

Access management

  • Google Cloud IAM with role-based access control and least-privilege principles.
  • Quarterly access reviews for all administrative accounts and entitlements.
  • Automated deprovisioning on employee status changes.
  • Comprehensive audit logging of all access and administrative actions.
  • Restricted physical access via Google Cloud data-centre controls (CCTV, biometrics, guards).

Secure software development

Security in every phase.

Development

  • OWASP-aligned secure coding standards
  • Mandatory peer code review
  • Static Application Security Testing (SAST)
  • Threat modelling and security requirements

Testing

  • Dynamic Application Security Testing (DAST)
  • Automated vulnerability scanning
  • Input validation and injection prevention
  • Production and non-production segregation

Release

  • CI/CD pipeline with security gates
  • Automated testing before deployment
  • Change management with risk assessment
  • Debug-code removal verification

GitHub security controls

Private repositories with MFA enforcement, role-based access, and audit logging. Source-code access is restricted to authorised developers only.

Network and application security

Multi-layered defence.

Cloud Armor WAF

  • L3/L4/L7 DDoS protection, with Google's global Anycast network absorbing volumetric attacks.
  • Rate limiting and throttling to prevent abuse and resource exhaustion.
  • Adaptive protection with automatic rule tuning based on traffic patterns.
  • Deep packet inspection for detecting and blocking malicious payloads.

Network controls

  • VPC firewall rules with default-deny and least-privilege network access.
  • Network segmentation isolating production, staging, and development.
  • VPC Flow Logs monitored for network-anomaly detection.
  • Quarterly firewall-rule reviews with business-justification documentation.

Application security

  • Input validation and parameterised queries preventing SQL injection.
  • Output encoding preventing cross-site scripting (XSS).
  • ModSecurity WAF providing host-based application-layer inspection.
  • API security with authentication, rate limiting, and IP filtering.
  • Secure error handling preventing information disclosure.
  • Tenant isolation via authentication and database segregation.

Operating-system hardening

  • Ubuntu LTS with minimal services and automatic security updates.
  • Baseline hardening following industry best practice (CIS benchmarks).
  • Critical patches applied immediately, with customer notification.

Monitoring and incident response

Continuous visibility, rapid response.

Continuous monitoring

  • Google Cloud Operations for infrastructure and application performance monitoring.
  • Comprehensive audit logging of all administrative actions and security events.
  • Automated alerting for suspicious activity and threshold violations.
  • Log retention with tamper-proof storage and restricted access.
  • Regular log reviews for security-event analysis.

Incident management

  • Formal incident-response policy with defined roles and procedures.
  • Rapid escalation paths for security incidents.
  • Customer notifications for incidents affecting service availability or data.
  • Post-incident reviews and a continuous-improvement process.
  • Vulnerability disclosure programme via .

Compliance and independent testing

Verified through regular assessment.

Penetration testing

  • Annual external testing by independent third-party security firms.
  • OWASP/PTES methodology covering network and application layers.
  • Remediation verification with follow-up retesting.

Internal audits

  • Quarterly access-control audits reviewing accounts and permissions.
  • Regular logging audits with monitoring and periodic reviews.
  • SDLC control audits ensuring secure development practices.
  • Annual policy reviews keeping documentation current.

Standards and frameworks

Development

  • OWASP SAMM
  • Secure SDLC
  • SAST / DAST

Architecture

  • CSA best practices
  • Google Cloud Security Reference
  • Defence in depth

Data protection

  • NIST 800-88 (secure deletion)
  • NIST SP 800-57 (key management)
  • GDPR

Business continuity and resilience

Built for availability and recovery.

Multi-region deployment

Active deployment across multiple GCP regions (US Central, Europe West, Europe North) for high availability and data residency.

Backup and disaster recovery

Automated daily backups with immutable storage, Google Cloud Backup and DR for point-in-time recovery, and tested restore procedures.

High availability

A 99.9% uptime SLA, supported by redundant infrastructure, automated failover, and 24/7 monitoring with alerting.

Change management

The Platform Update Policy defines risk-based change categories with appropriate notification windows and rollback procedures:

Patch

Immediate, security-critical fixes

Maintenance

Minor updates, 24h notice

Minor

Feature updates, 72h notice

Major

Breaking changes, two weeks' notice

Security contact.

We welcome security researchers, customers, and collaborators to contact us on security matters. For vulnerability disclosures, please include detail on the issue, steps to reproduce, and any supporting materials. We typically respond within one to two working days.

Security, privacy, and general enquiries

Security documentation is available to enterprise customers on request.