CipherStashDocs
SecurityCompliance

Compliance

How CipherStash capabilities support a compliance control design, and which responsibilities remain with the customer.

CipherStash supplies technical controls that can support a compliance program: field-level encryption, regional key management, cryptographic isolation, identity-bound decryption, and data-access evidence. A framework outcome still depends on how those controls are configured and on the surrounding application, cloud, operational, and organizational controls.

Capability map

Requirement areaRelevant CipherStash capabilityCustomer responsibility
Protect sensitive stored dataApplication-level field encryptionClassify fields and ensure every write path encrypts them
Restrict key accessClient keys, access-key roles, and keyset grantsApply least privilege, rotate credentials, and control the deployment secret store
Isolate tenants or environmentsSeparate keysets or workspacesDefine and enforce the boundary consistently in application and database access
Attribute access to a userOIDC federation and lock contextsConfigure the identity provider and choose stable, appropriate claims
Produce data-access evidenceZeroKMS derivation context and Proxy audit eventsConfigure retention, review, alerting, and SIEM ingestion
Keep key material regionalRegion-bound workspacesDeploy applications and databases in the intended region and govern cross-border access
Remove access to encrypted dataRevoke client grants or destroy the relevant key boundaryConfirm scope, backups, legal holds, and recovery requirements before destructive action

Common frameworks

These capabilities can contribute evidence or control implementation for frameworks such as SOC 2, HIPAA, GDPR, PCI DSS, ISO 27001, and regional privacy laws. They do not by themselves make a workload compliant, and the exact mapping depends on the organization's scope and assessor interpretation.

Use the following pages when building a control narrative:

Contact [email protected] for current assurance reports, contractual documents, or framework-specific questions.

On this page