SlateBeaverSlateBeaver
SlateBeaverSlateBeaver
Log in
Security & trust

Security is our entire product.
Not a tab in the settings.

The question an auditor always asks is “who accessed that credential, and why?” Most companies can’t answer it. SlateBeaver makes it answerable before they ask.

AES-256-GCM encryption
at rest & in transit (TLS 1.3)
Per-credential RBAC
9 roles, explicit grants only
Immutable audit trail
tamper-evident, SIEM exportable
Organisation isolation
complete data separation
Encryption

AES-256-GCM at rest. TLS 1.3 in transit.

Every credential stored in Aegis is encrypted with AES-256-GCM before it leaves your browser. Each record gets a unique 96-bit nonce. Keys are wrapped using envelope encryption with AWS KMS or GCP Cloud KMS.

Algorithm
AES-256-GCM (NIST SP 800-38D)
Key management
AWS KMS / GCP KMS envelope encryption
Key rotation
Automated every 90 days; manual on-demand
In-transit
TLS 1.3 minimum; HSTS preloaded
Infrastructure

Region-pinned, multi-cloud, and separated by design.

SlateBeaver runs across AWS and GCP with region-aware storage, isolated application services, and append-only audit systems separated from transactional data. Credential values, audit events, and key-management boundaries are not collapsed into one datastore.

Application layer
Auth gateway, Aegis API, Aero API, audit service
Tenant isolation
Workspace-scoped isolation with region pinning for IN / EU
Key custody
Envelope encryption with AWS KMS or GCP KMS
Backup model
Encrypted rolling backups with 7-day retention
Infrastructure architecture
CLIENT TIER
CLI (sb)
Web app
API clients
CI/CD runners
↓ TLS 1.3 (enforced)
API TIER · AWS + GCP · Multi-region
Auth gateway (SAML/OIDC)
Aegis API
Aero API
Audit service
↓ AES-256-GCM (envelope encryption, per-secret keys)
DATA TIER · Region-pinned · Isolated per tenant
Encrypted store (IN/EU)
Audit log (append-only)
Key management (AWS KMS / GCP KMS)
Backups (7-day)
Identity & access

MFA, SSO, hardware keys, and JIT.

SlateBeaver enforces multi-factor authentication on every account. Business and Enterprise plans support SAML 2.0 and OIDC SSO. Hardware key support via WebAuthn. Session lifetime is 8 hours with configurable idle timeout.

MFA types
TOTP, SMS, WebAuthn (hardware keys)
SSO
SAML 2.0, OIDC - Okta, Azure AD, Google
Session management
8h lifetime, idle timeout configurable
Just-in-time access
Temporary grants with automatic expiry

Aegis's audit trail and RBAC are built specifically to support SOC 2, ISO 27001, and GDPR audits.

Audit trail

Append-only. Cryptographically chained. Exportable.

Every action in Aegis - every reveal, edit, export, grant, and revoke - is written to a tamper-evident, append-only log. Entries are chained with SHA-256 hashes. Export to Datadog, Splunk, or raw JSON via API.

Sample audit events
14:02:11m.rao revealed STRIPE_SECRET_KEYREVEAL
13:47:02s.kapoor granted engineer JIT access (2h)GRANT
11:08:21d.okoro exported .env (watermarked)EXPORT
10:52:00s.kapoor revoked contractor-tmp@ accessREVOKE
Retention
90 days Business · Unlimited Enterprise
Export formats
JSON, CSV, Splunk, Datadog
Tamper detection
SHA-256 chain, verified on read
SIEM integrations
Datadog, Splunk, Elastic (native)
Vulnerability disclosure

Safe-harbor, 90-day deadline, hall of fame.

We operate a coordinated disclosure program. If you find a vulnerability, email security@slatebeaver.com. We promise to acknowledge within 12 hours and resolve Critical issues within 7 days. PGP key available on request.

-----BEGIN PGP PUBLIC KEY BLOCK-----
Key-Type: RSA
Key-Length: 4096
Name-Real: SlateBeaver Security Team
Name-Email: security@slatebeaver.com
Fingerprint: 3F1A 9B2C ...
-----END PGP PUBLIC KEY BLOCK-----
Compliance

Frameworks we’re audited against.

GDPR

Data processing agreements available. EU data residency option.

SOC 2 Type II

All five trust service criteria. Annual renewal.

ISO 27001

Information security management. Certified Nov 2025.

HIPAA Ready

BAA available on Enterprise plans.

PCI DSS

In scope assessment planned Q4 2026.

CCPA

California privacy law compliant. Privacy controls in dashboard.

Availability

Three nines to four nines, depending on plan.

All systems operational
status.slatebeaver.com
PlanUptime SLAResponse
Starter99.5%Next business day
Business99.9%4-hour SLA
Enterprise99.95%1-hour SLA

Questions about our security posture?

Our security team responds to disclosures and reviews within 12 hours. For enterprise security assessments, contact sales.

Contact security →