Security

Useful signal. Protected context.

KYSTA combines transport security, user isolation, field encryption and narrow operational access without pretending any internet service is risk-free.

Data isolation

Available now

User-owned database tables use PostgreSQL row-level security. Runtime access is scoped to the authenticated effective user. Administrator impersonation is permissioned, time-bounded and audited.

Sensitive text

Available now

Reflective notes and supported short-text evidence are encrypted at rest with authenticated field context. KYSTA decrypts them when returning the data to the owner. This is field-level encryption, not end-to-end encryption.

Recovery and access

Production uses HTTPS, separate application and migration database roles, encrypted independent backups and controlled administrator access. Report a security concern privately to privacy@kysta.app or support@kysta.app.