Encrypted in transit and at rest
Every connection runs over TLS, including a door tablet talking to Entry Keep across a site network. Visit records, uploaded documents, and backups are all encrypted at rest.
Security
Entry Keep holds names, arrival times, and sometimes identity documents. Keeping that data safe comes before everything else, and it is why we build the way we do.
Every connection runs over TLS, including a door tablet talking to Entry Keep across a site network. Visit records, uploaded documents, and backups are all encrypted at rest.
When a site captures an identity document number, Entry Keep keeps only a one-way hash of it. That is enough to match a visitor against the blocklist, but the original number can never be read back. Not by another visitor, not by a site’s own staff, and not by Entry Keep itself.
Row-level security keeps each organization’s data walled off from every other. One organization’s visits, hosts, and blocklist can never show up in another’s.
Check-ins, check-outs, blocklist edits, and settings changes are all recorded, each with the person who did it and the time it happened. If a record is corrected later, that change is recorded too, so the history always shows what really happened.
A guard account handles checking visitors in and out. Reading further back through the history and changing settings are admin permissions, kept to the people who need them.
An admin sets how much history everyone else can look through. You can open up the last week or the last month to the team and keep older visits to admins only. It does not change how anyone checks a visitor in, only how far into the past they can read.
Signing in happens on secure hosted pages, so Entry Keep never sees or stores your password.
A visit can be recorded with a name alone. Capturing a document number is a setting that is off by default. When it is on, the number is checked against the blocklist and kept only as a hash. It is never shown again, not even to a manager.
When a visitor asks to be removed, or you close your account, the records are purged. Deleting really means the data is gone, not just hidden from view.
If your organization must keep its records in a specific region to meet local data legislation, the Enterprise plan gives you your own dedicated instance, hardened and more secure, in the region your data lives in.
If you find a vulnerability, email info@entrykeep.com and we will take it from there.