Business access is checked on the server
Operational requests are scoped to the signed-in user’s business and permitted role. The private platform-admin portal has a separate owner allowlist; being a customer’s Owner does not grant platform-admin access. Where independent customer access is enabled, requests require verified email/password credentials and an active subscription or card-backed trial. Missing subscription records, sandbox payments and expired trials cannot unlock business data. Independent public signup is not yet operational.
Files and exports
File access is checked against business membership. Uploads have type, size and storage-quota checks. CSV exports and owner backup downloads are available. Backup recovery has been exercised locally, but scheduled off-site backups and a hosted disaster-recovery test are still outstanding.
What is not claimed
Keepalto does not claim SOC 2 certification, ISO 27001 certification, a contractual uptime guarantee, UK-only hosting, enterprise SSO or an independent penetration test. A separately prepared Supabase database has passed isolation checks, but is not yet the live app’s data store.
Report a concern
Email support@phantiqstudios.com with ‘Keepalto security’ in the subject and include the affected page, time and a minimal description. Do not send passwords, access tokens or other people’s records. Do not test against other businesses’ data. There is no advertised round-the-clock response SLA or bug-bounty programme. The standard security.txt file publishes the same contact and this policy location.