Confidentiality & Privacy
How Gatana Cloud protects your sensitive data with SOC 2-grade encryption
On-Premise & Self-Hosting
For complete data-ownership, you can self-host Gatana, see On-Premise & Self-Hosting for more information.
Overview
Gatana Cloud protects all sensitive customer data using Google Cloud Key Management Service (KMS) and envelope encryption1. Credentials, API keys, and other sensitive information remain protected even in the event of a database breach.
Each organization has its own encryption key, providing complete cryptographic separation between organizations. Keys are rotated according to security best practices.
For additional isolation, secret stores allow you to store credentials in your own vault and have Gatana retrieve them at runtime.
Envelope Encryption
Gatana uses envelope encryption to protect sensitive data. Each organization is assigned a unique AES-256-GCM data encryption key (DEK) that encrypts all sensitive information within that organization. The DEK itself is encrypted by Google Cloud KMS and stored in this protected form. At runtime, Gatana decrypts the DEK using KMS and retains it in memory only for the duration required to perform cryptographic operations.
Self-hosted installs
Self-hosted installs choose which key manager wraps the DEK, with the Helm value kms.provider:
kms.provider | What wraps the DEK | Also set |
|---|---|---|
gcp | Google Cloud KMS | kms.gcpKeyId |
aws | AWS KMS | kms.aws.keyId (key ARN, alias/<name>, or key ID) |
none (default) | Nothing. Sensitive values are stored as-is, protected only by disk encryption |
For AWS, the backend needs kms:Encrypt and kms:Decrypt on the key. It picks up credentials from the
usual chain (IRSA, EKS Pod Identity, or the node role). If those credentials belong to something else,
such as SES, give the KMS client its own keys through kms.aws.credentialsSecret. A key given as a full
ARN also names its region, so kms.aws.region is only needed for an alias or a bare key ID.
Questions
If you have questions about our security practices, please contact [email protected].
Footnotes
-
Gatana is not yet SOC 2 certified, we are actively working together with an implementation parter towards certification. ↩