Security

Useful signal. Protected context.

KYSTA combines transport security, user isolation, field encryption and narrow operational access without pretending any internet service is risk-free.

Data isolation

Available now

User-owned database tables use PostgreSQL row-level security. Runtime access is scoped to the authenticated effective user. Administrator impersonation is permissioned, time-bounded and audited.

Sensitive text

Available now

Reflective notes and supported short-text evidence are encrypted at rest with authenticated field context. KYSTA decrypts them when serving an authorised request or preparing an export. Access is also possible through permissioned, time-bounded and audited administrator impersonation. This is field-level encryption, not end-to-end encryption.

How field encryption works

Reflective activity notes and supported short-text measurements use AES-256-GCM. A random per-user seed combines with an application secret to derive the key. Authentication binds the encrypted value to its user, record and field.

KYSTA holds the application secret; the user does not hold an exclusive decryption key. Numerical evidence remains queryable for totals and patterns. A portable export includes readable notes, without keys or credentials.

Recovery and access

Production uses HTTPS, separate application and migration database roles, encrypted independent backups and controlled administrator access. Report a security concern privately to privacy@kysta.app or support@kysta.app.