Vertrauen und Sicherheit

Sicherheit und Compliance.

Sicherheit ist keine Funktion, die wir hinzufügen. Sie ist das Fundament, auf dem alles bei Skycloak aufgebaut ist. Von unserer Multi-Cloud-Infrastruktur bis zu Mitarbeiter-Zugriffskontrollen ist jede Ebene darauf ausgelegt, Ihre Daten zu schützen und die höchsten Compliance-Standards zu erfüllen.

SOC 2-, ISO 27001- und GDPR-Berichte auf Anfrage verfügbar.

Compliance Zertifizierungen.

Wir führen strenge Drittanbieter-Audits und Zertifizierungen durch, damit Ihre Sicherheits- und Compliance-Teams uns nicht beim Wort nehmen müssen. Berichte sind auf Anfrage verfügbar.

SOC 2 Type II

Independently audited across all five Trust Service Criteria: Sicherheit, Availability, Confidentiality, Processing Integrity, and Privacy.

Compliant

ISO 27001

Certified information sicherheit management system covering risk assessment, Zugriffskontrolle, encryption, incident management, and business continuity planning.

Certified

GDPR

Vollständige Compliance mit der EU-Datenschutz-Grundverordnung. Standard Contractual Clauses (SCCs) verfügbar für internationale Datenübertragungen. Data Processing Agreements auf Anfrage.

Compliant

HIPAA

HIPAA-compliant and BAA-ready for healthcare workloads. Aligned with the HIPAA Sicherheit and Breach Notification Rules and backed by our SOC 2 Type II and ISO 27001 controls. Business Associate Agreements available.

BAA available
Visit the Trust Center

Five-layer defense in depth.

Every request to your Keycloak instance passes through five distinct sicherheit layers, each independently hardened and monitored.

1

Edge Protection

Cloudflare bietet DDoS-Mitigation, Web Application Firewall (WAF)-Regeln und TLS-Terminierung am Edge, bevor der Traffic unsere Infrastruktur erreicht.

2

Network Isolation

Private virtual networks with network Zugriffskontrolle lists and sicherheit groups enforce strict ingress and egress rules on every cloud we run on. No internal services are exposed to the public internet.

3

Service Mesh

Ein dediziertes Service Mesh erzwingt gegenseitiges TLS (mTLS) zwischen allen Services. Jede interne Kommunikation wird auf der Transportschicht verschlüsselt und authentifiziert.

4

Application Sicherheit

Keycloak läuft in gehärteten Containern mit Read-Only-Dateisystemen, Non-Root-Prozessen und Ressourcenlimits. Application-Level-Firewalls filtern bösartige Anfragen.

5

Data Encryption

AES-256-Verschlüsselung im Ruhezustand mit Hardware-gestütztem Key Management. TLS 1.3 für alle Daten in Transit.

Infrastruktur sicherheit.

Your Keycloak instance runs on hardened cloud infrastructure with complete tenant isolation across dedicated compute, datenbank, and credential boundaries.

Isolated Environments

Produktions- und Entwicklungsworkloads laufen in vollständig isolierten Cloud-Umgebungen. Produktionsinfrastruktur ist mit strikten IAM-Richtlinien und getrennten Zugriffskontrollen gesichert.

Complete Tenant Isolation

Every customer gets dedicated compute resources, a dedicated datenbank, and dedicated credentials. No shared datenbank tables, no shared instances, no noisy-neighbor risk.

Regionen weltweit

Stellen Sie in der Region am nächsten zu Ihren Benutzern bereit: US East (Ohio), EU Central (Frankfurt), Asia Pacific (Sydney) oder Canada (Central). Daten bleiben in Ihrer gewählten Region.

Continuous Überwachung

Real-time health checks, performance Überwachung, and automated alerting. Self-healing mechanisms automatically replace unhealthy instances without manual intervention.

Encryption everywhere.

Alle Daten werden in transit und im Ruhezustand mit branchenüblichen kryptografischen Protokollen und hardwaregestütztem Schlüsselmanagement verschlüsselt.

Data in Transit

  • TLS 1.3 for all external communications
  • Mutual TLS (mTLS) between all internal services
  • AEAD-256 encrypted datenbank cluster communications
  • Perfect Forward Secrecy on all connections

Data at Rest

  • AES-256 encryption for all stored data
  • Hardware-backed key management with automated rotation
  • Encrypted Sicherungs and snapshots
  • Kundendaten auf Feldebene verschlüsselt, wo zutreffend

Token Sicherheit

  • Short-lived access tokens with configurable lifetimes
  • Refresh token rotation on each use
  • Instant token revocation Fähigkeity
  • Cryptographically signed JWTs with RS256/ES256

Modell der geteilten Verantwortung.

Als Managed Keycloak-Anbieter übernehmen wir die Infrastruktur und den Betrieb, damit Sie sich auf Ihre Anwendung konzentrieren können. Hier ist genau, wo die Grenze verläuft.

Skycloak Manages
  • Keycloak infrastructure provisioning & scaling
  • Operating system & container patching
  • Keycloak version Upgrades & CVE tracking
  • Datenbank management, Sicherungs & disaster recovery
  • Network sicherheit, firewalls & DDoS protection
  • TLS certificates & encryption key management
  • Überwachung, alerting & incident response
  • SOC 2, ISO 27001 & GDPR-Compliance der Infrastruktur
  • High availability & automatic failover
You Manage
  • Realm configuration & authentifizierung policies
  • Benutzerverwaltung & Zugriffskontrolle rules
  • Client application configuration & secrets
  • Custom themes & login page branding
  • Integration sicherheit with your applications
  • Password policies & MFA enforcement choices
  • Identitätsanbieter federation setup
  • Compliance der Daten, die Sie in benutzerdefinierten Attributen speichern
  • End-user communication & consent flows

Datenresidenz & Datenschutz.

Sie wählen, wo Ihre Daten liegen. Wir stellen sicher, dass sie dort bleiben, mit strikten Kontrollen und transparenten Datenverarbeitungspraktiken.

Regionsauswahl

Deploy in US East (Ohio), EU Central (Frankfurt), Asia Pacific (Sydney), or Canada (Central), with more regions added over time. Your data, including Sicherungs and logs, never leaves your chosen region.

International Transfers

Für grenzüberschreitende Datentransfers verlassen wir uns auf Standard-Vertragsklauseln (SCCs), wie von der Europäischen Kommission genehmigt. Datenverarbeitungsverträge sind auf Anfrage verfügbar.

Data Retention

Audit logs retained up to 365 days depending on plan (90 days default). Automated datenbank Sicherungs retained for 7 days. Upon account termination, a 60-day grace period is provided for data export, after which all data is permanently deleted.

Subprocessors

Our infrastructure runs across multiple cloud providers, including AWS, Azure, GCP, OVH, Akamai, and Scaleway, depending on region, and Cloudflare provides edge sicherheit (DDoS protection, WAF, TLS termination). We do not use third-party analytics, Überwachung, or tracking services that access your customer data. Full subprocessor list available on request.

Geschäftskontinuität & Incident Response.

Strukturierte Disaster-Recovery-Verfahren und schwerebasierte Incident Response, um Ausfallzeiten zu minimieren und Sie informiert zu halten.

Disaster Recovery

Near-Zero
Recovery Point (RPO)
10-30 min
Recovery Time (RTO)
99.99%+
Verfügbarkeits-SLA
  • Daily automated snapshots with point-in-time recovery
  • Warm standby option in a separate region
  • Automated self-healing for cluster health issues
  • DR-Test-Kadenz: tägliche Verifikation, wöchentliche PITR-Tests, monatliche Failover-Drills, vierteljährliche vollständige DR-Übungen

Incident Response

Alle Vorfälle werden nach Schweregrad mit definierten Benachrichtigungszeitlinien klassifiziert:

SeverityDescriptionNotification
CriticalActive data breach or complete service outageWithin 1 hour
HighSignificant service degradation or potential breachWithin 4 hours
MediumLimited impact, no data compromiseWithin 24 hours
LowMinor issue, no user impactWithin 72 hours

Personnel sicherheit.

The sicherheit of your data depends on the people who manage it. Every team member follows strict sicherheit practices from day one.

Background checks for all employees before hire
Mandatory annual sicherheit awareness training
MFA erforderlich für alle internen Systeme, keine Ausnahmen
Least-privilege access with quarterly reviews
Continuous compliance Überwachung and evidence collection
Segregation of duties across infrastructure roles

Sicherheit assessments.

Regular testing by independent sicherheit firms, continuous vulnerability scanning, and transparent reporting, with reports available on request.

Penetration Testing

Jährliche Penetrationstests durch Dritte nach der OWASP Testing Guide-Methodik. Ergebnisse und Sanierungsberichte auf Anfrage verfügbar.

Vulnerability Scanning

Kontinuierliches automatisiertes Scannen von Infrastruktur und Abhängigkeiten. Keycloak CVEs werden aktiv verfolgt, betroffene Instanzen werden prompt auf gepatchte Versionen aktualisiert.

Code Reviews

All infrastructure changes undergo peer review and automated sicherheit checks before Bereitstellung. Secure SDLC practices enforced across all codebases.

Verantwortungsvolle Offenlegung.

Wir schätzen die Arbeit von Sicherheitsforschern. Wenn Sie glauben, eine Sicherheitslücke in Skycloak gefunden zu haben, möchten wir davon hören.

Report to:
Response time:Acknowledgment within 2 business days
Resolution target:Critical issues triaged within 24 hours

Bitte geben Sie detaillierte Reproduktionsschritte an und gewähren Sie uns angemessene Zeit zur Untersuchung und Behebung vor öffentlicher Offenlegung. Wir nennen Forscher, die gültige Befunde melden, auf Anfrage.

Sicherheit FAQ.

Common questions from sicherheit and procurement teams.

Can I get a copy of your SOC 2 Type II report?
Yes. Our SOC 2 Type II report is available to customers and prospects under NDA. Contact us to request access, and our team will share it, along with our ISO 27001 certificate and other compliance documentation.
Where is my data stored?
You choose the region: US East (Ohio), EU Central (Frankfurt), Asia Pacific (Sydney), or Canada (Central), with more regions added over time. Your data, including backups and logs, stays in your chosen region.
Is customer data shared between tenants?
No. Every customer runs in its own fully isolated tenant with dedicated resources, so there is complete tenant isolation and no noisy-neighbor risk. For the architecture details, reach out.
What happens if there is a security incident?
Incidents are classified by severity with defined notification timelines: Critical within 1 hour, High within 4 hours, Medium within 24 hours, and Low within 72 hours. We follow a structured incident response process and keep you informed throughout.
How do you handle Keycloak CVEs?
We actively track Keycloak CVEs and security advisories. Affected instances are upgraded to patched versions promptly as part of managed version upgrades, so you are not left running vulnerable releases.
Do you have a Data Processing Agreement (DPA)?
Yes. A GDPR-compliant Data Processing Agreement is available on request, along with Standard Contractual Clauses (SCCs) for international data transfers.
What subprocessors do you use?
Our infrastructure runs across multiple cloud providers, including AWS, Azure, GCP, OVH, Akamai, and Scaleway, depending on region, and Cloudflare provides edge security (DDoS protection, WAF, TLS termination). We do not use third-party analytics, monitoring, or tracking services that access your customer data. A full subprocessor list is available on request.
Do you support SSO for admin access?
Yes. You can federate admin access to your own identity provider over OIDC or SAML, and MFA can be enforced. Internally, MFA is required on all Skycloak systems with no exceptions and access follows least-privilege with quarterly reviews.

Looking for sicherheit Funktions?

Explore our advanced sicherheit add-ons including WAF, DDoS protection, rate limiting, geo-blocking, and more.

Ansehen Sicherheit Funktions

Questions about sicherheit?

Our team is ready to discuss your sicherheit and compliance requirements. Request our SOC 2 report, schedule a sicherheit review, or report a concern.

SOC 2 Type II Compliant DSGVO-konform ISO 27001 zertifiziert
Vertrieb kontaktieren Kostenlos testen
© 2026 Skycloak. Alle Rechte vorbehalten. Design von Yasser Soliman