Explore Keepalto

TRUST & TRANSPARENCY

Clear about what protects your records.

Security claims should describe what is running, not what is on a roadmap. This page reflects the current evaluation platform.

Business access is checked on the server

Operational requests are scoped to the signed-in user’s business and permitted role. The private platform-admin portal has a separate owner allowlist; being a customer’s Owner does not grant platform-admin access. Customer requests require verified email/password credentials and an active subscription or card-backed trial. Missing subscription records, sandbox payments and expired trials cannot unlock business data.

Files and exports

File access is checked against business membership. Uploads have type, size and storage-quota checks. CSV exports and owner backup downloads are available. Backup recovery has been exercised locally, but scheduled off-site backups and a hosted disaster-recovery test are still outstanding.

What is not claimed

Keepalto does not claim SOC 2 certification, ISO 27001 certification, a contractual uptime guarantee, UK-only hosting, enterprise SSO or an independent penetration test. A separately prepared Supabase database has passed isolation checks, but is not yet the live app’s data store.

Report a concern

Email support@phantiqstudios.com with the affected page, time and a brief description. Do not send passwords, access tokens or other people’s records. Do not test against other businesses’ data. There is no advertised round-the-clock response SLA.