Skip to content

Legal Center

Security Overview.

A high-level summary of how Keystone IQ protects your portfolio data — written for a prospective customer or their IT/security reviewer. Last updated July 2026.

How we protect your data

This page is a plain-language summary for anyone evaluating Keystone IQ — an owner, an investor, or the IT/security reviewer on their team. It's intentionally high-level; for the full data-handling picture (what we collect, why, and who we share it with), see our Privacy Policy.

Encryption

All traffic between your browser and our servers is encrypted in transit over TLS. Your database and file storage are encrypted at rest using our cloud provider's managed encryption. Bank-connection tokens (via Plaid) receive an extra layer of protection on top of that: they're separately encrypted at rest before being stored, so a plaintext bank-connection token never touches our logs or sits unencrypted in the database.

Secrets management

API keys, database credentials, and every other credential our systems use live in a dedicated cloud secret-management service. None are committed to our source code or left sitting in plaintext configuration files.

Multi-tenant data isolation

Keystone IQ is multi-tenant software — every customer's portfolio lives in the same database, scoped to their organization.

Every database query is scoped to your organization ID at the connection layer. Customer-to-customer isolation is absolute — another customer's session can never reach your data. Keystone IQ operators are governed separately (see Operator Access). See Trust & Operator Access for the full detail on what limited administrative access we do have.

Sign-in and account protection

You can sign in with an email and password, or with your Google or Apple account. Sign-in is handled by Firebase Authentication — the same identity platform behind many everyday consumer and business apps. Passwords are never stored by us in a form anyone can read, and each sign-in session expires on its own so an old, forgotten session can't be reused indefinitely.

If you use an email and password, you can turn on optional two-factor authentication (2FA): a second step at sign-in using an authenticator app, so a stolen password on its own isn't enough to reach your account. When you turn it on we also give you one-time backup codes to save, so losing your phone doesn't lock you out. (If you sign in with Google or Apple, your account is already covered by that provider's own two-factor settings.)

On the mobile app — iPhone and Android — you can additionally lock the app behind your device's own biometric unlock (Face ID or Touch ID on iPhone, fingerprint or face unlock on Android). And after a stretch of inactivity, the app asks you to confirm it's still you before it unlocks again — a screen-lock for your portfolio, without signing you all the way out.

Monitoring

We run automated error tracking across our applications and keep an audit log of account-level actions. Uptime and system health are checked automatically around the clock, so we typically know about a problem before you do.

Payment security

Keystone IQ never sees or stores your raw card number. Payment details are collected directly by Stripe's own PCI-compliant embedded payment form and never pass through our servers — which keeps Keystone IQ in the lightest tier of card-data compliance scope (SAQ A), rather than handling card data ourselves.

Vendor selection

We deliberately keep our list of third-party processors short, and we choose each one for its own strong security track record rather than picking whatever's cheapest or newest. See our Sub-Processors page for the full, current list and what each one is used for.

Responsible disclosure

If you're a security researcher and you've found something that concerns you, we want to hear about it. Please email support@keystoneiq.app with what you found — we read every report and follow up directly.

Have a question this page doesn't answer? Email us at support@keystoneiq.app.