kombine.work

Data security

Grouped rather than listed, because the question is usually narrower than the whole page: who can get in, what happens to the data, and how you would know afterwards.

These apply to the hosted service. On a self-hosted installation the application-level measures are identical, because it is the same build, while the infrastructure ones become yours to run.

Who can get in

Multi factor authentication

Available on every account and required for administrators. Enforced at sign-in rather than offered as a preference somebody can decline.

Single sign on

Through your own identity provider, which hands the decision back to you along with your own conditional access rules, session policies and joiner-leaver process.

Permissions per module

Each of the seventeen modules can be granted read, write or admin independently per role, and some read levels are owner-scoped so a person sees only their own records. An auditor can be given the whole record with no ability to change it.

Session revocation

Sessions can be revoked, for one person or for an entire company, in a single action. Useful on the day somebody leaves and essential on the day something goes wrong.

Restricted by address

A company can restrict its own workspace to named IP ranges, so a stolen password is not enough on its own.

What happens to the data

Hosted in the European Union

Stockholm, eu-north-1. Customer data does not leave the EU in the hosted service. Every sub-processor, its role and its region is published in the data processing agreement rather than summarised in a clause.

Encrypted at rest

Volumes are encrypted, and so are the backups taken from them.

Encrypted in transit

TLS everywhere, including between the collectors and the platform, and between the platform and every system it reads.

Credentials encrypted individually

The credentials you hand over for integrations are encrypted field by field in the database, under a separate key from the data itself. Those are the keys worth stealing, so they are not protected by the same measure as everything else.

Your data comes back

A full export is available in the application for the whole subscription, so getting your data out never depends on us being cooperative. After termination the workspace is kept for 30 days so an export is still possible, then deleted.

How you would know

Everything is logged

Every change and every machine to machine upload leaves an audit entry naming who or what did it and when. Entries stay live for at least ninety days and are archived encrypted after that, so a question asked a year later still has an answer.

Signed collector agents

The agents ship as signed packages and update themselves from signed packages. They collect and do nothing else on the machine.

Backups and tested restores

Backups run nightly across three tracks, and restores are tested rather than assumed. A backup nobody has restored is a belief, not a control.

Scanned on every build

Dependencies and container images are scanned on every build, and the platform is penetration tested by an external party. Findings are tracked to closure in the same register our customers use for theirs.