Trust & Security
Your formulas are trade secrets.
We treat them that way — at every layer.
Kemist is built on defense in depth: multiple independent controls, so that a single failure can never expose your data to another customer.
How we protect your data
Your data is yours alone — isolated at every layer
Every request is scoped to your organization, and membership is verified for every user — there is no admin back door. The data-access layer enforces isolation by construction, and the database itself can deny cross-tenant access as an independent backstop.
Trade secrets stay secret — even when you share
Share a formula externally and recipients see an ingredient (INCI) list and benign metadata — never percentages, costs, or suppliers. That trade-secret floor is enforced on our servers, not by hiding fields in the browser.
Least privilege by default
Role-based access, per-product entitlement, and field-level visibility mean people see exactly what their role allows — enforced on the server, not just the screen.
A tamper-evident record of everything that matters
Security-relevant actions are written to an append-only, cryptographically hash-chained audit log with daily integrity snapshots — the defensible trail regulated teams and auditors expect.
Built for your compliance obligations
Our controls are built to align with SOC 2, ISO 27001, and GDPR expectations — tenant isolation, MFA, encryption at rest, data-subject access and erasure, and an auditable evidence trail.
Aligned with the standards your reviewers expect
Kemist's controls are built to align with SOC 2, ISO 27001, and GDPR expectations — tenant isolation, MFA, encryption at rest and in transit, data-subject access and erasure, and an auditable evidence trail.
Built to align with:
We're upfront about where we are.
Kemist is not currently SOC 2 or ISO 27001 certified. Our controls are built to align with these frameworks, we maintain the supporting evidence trail an auditor would request, and we intend to pursue formal SOC 2 Type II attestation. Evidence is available on request under NDA.
Under the hood
Authentication
MFA, short-lived privileged sessions, immediate session revocation, and a token design that prevents lower-purpose tokens from being replayed as access tokens.
Provisioning safety
Identity is never auto-linked from a self-asserted email — closing a common account-takeover vector.
Encryption
Envelope encryption (master key → per-purpose key → record key) plus field-level encryption for sensitive data, and TLS in transit.
Data lifecycle
Immutable version history with a governed erasure path for GDPR data-subject requests.
Evaluating Kemist for a regulated team?
We'll walk your security and compliance stakeholders through our controls and share our security overview.
Request a security review