Security & trust

Security controls that support real operational responsibility.

Soteria’s Key is designed for professional, authorized use. The public security posture centers on constrained access, minimum-necessary information, traceable workflows, and clear responsibility boundaries.

01

Authorized access

Operational functionality is kept behind authenticated access for participating organizations and authorized users.

02

Role-aware permissions

Administrative and operational responsibilities are separated so access can be scoped to the user’s role and organizational need.

03

Data minimization

Workflows are designed around the information needed to coordinate authorized activity rather than collecting unnecessary personal detail.

04

Operational traceability

Placement and administrative workflows are structured to support accountability for authorized actions and operational follow-through.

Trust boundaries

The platform does not blur source evidence with operational fact.

Security is also about data integrity. Soteria’s Key keeps authoritative provider discovery information distinct from current operational availability and placement acceptance so users can understand what a data point actually supports.

Read about provider data →

Public trust principles

  • Least-privilege access patterns
  • Authentication for operational functionality
  • Separation of administrative and standard-user responsibilities
  • Source-aware provider information
  • No automatic inference of live capacity from directory data
Governance

Deployment requirements matter.

Organizational policy, configured permissions, hosting controls, executed agreements, and applicable legal requirements determine the final production operating model. This public page is a high-level posture summary, not a certification or contractual attestation.

Access governance

Participating organizations define who is authorized and which responsibilities those users should hold within the deployment.

Retention & policy

Data handling and retention requirements depend on the deployment, organizational policy, agreements, and applicable requirements.

No unsupported certification claims

Soteria’s Key does not represent a certification such as SOC 2, HIPAA, or CJIS compliance on this page unless an applicable formal attestation or agreement expressly supports that claim.

Security concern or vulnerability report?

Use the official contact pathway so the issue can be triaged through controlled procedures.

Contact the Team

Evaluating security for a pilot?

Start with the public posture here, then coordinate deployment-specific requirements with the platform team.