Kaffeine's security infrastructure is engineered by Equitus Corporation — a defense-technology firm whose clients include the U.S. Army, DHS, Lockheed Martin, and IBM. Every control is designed to protect your PHI, your downline, and your carriers.
7
Production Rust Microservices
55+
Database Tables
110+
Optimized Indexes
5
Concentric Defense Layers
AES-256
Encryption Standard
TLS 1.3
Transport Security
7-Year
Audit Log Retention
< 15 min
Critical MTTR
Defense in Depth
No single point of failure. Each layer independently blocks a class of threats — and continuously monitors for drift in the others.
Authorization & Decision Enforcement
Traditional CRM security is organized around Login → Role → Application Access. Kaffeine is designed around a continuously enforced decision chain that controls what every human, service, integration, workflow, and AI agent can do after they are inside — and explains and audits every consequential decision.
This model protects who can enter the CRM — then grants broad application-level permissions. Actions performed inside are not individually authorized, context is not evaluated per request, and decisions are not explained.
CRM operations execute inside a continuously enforced security perimeter. Not a SaaS app protected by controls — a high-assurance information environment where every identity, capability, action, decision, and transaction is bounded, explained, and traced.
Every identity is known.
Every privileged capability can be bounded.
Every sensitive action can require explicit authority.
Every important decision can be explained.
Every consequential transaction can be traced.
What this means in practice: humans, service accounts, third-party integrations, automated workflows, and AI agents are all treated as identities. Each is authenticated, assigned bounded capabilities, and evaluated against policy on every sensitive action — with the decision and its reasoning written to a tamper-proof audit trail. Nothing inside Kaffeine is trusted by default.
Compliance
We don't bolt compliance on at the end. Every control is designed into the architecture from day one.
HIPAA § 164.312(b)
6-step immutable audit trail with tamper-proof hash chain. All PHI access, modification, and export events are logged, timestamped, and retained for 7 years in compliance with HIPAA's audit control requirements.
HIPAA § 164.312(a)(2)
Session inactivity timeout enforced across all user tiers. Emergency access procedures documented and tested. Unique user identification for all PHI access — shared credentials are architecturally prevented.
HIPAA § 164.312(e)(2)
All ePHI encrypted with AES-256 at rest and TLS 1.3 in transit. PHI tokenized at ingestion — cleartext health data is never stored in application tables or logs.
SOC 2 Type II
Security, availability, and confidentiality controls continuously collected and evidence-ready. Automated control monitoring ensures drift is detected and remediated before audit cycles.
NIST 800-53
Architecture aligned to NIST 800-53 control families including AC (Access Control), AU (Audit), SC (System & Communications), and SI (System Integrity) — the same framework used by federal agencies.
DoD STIGs
Security Technical Implementation Guides (STIGs) applied to infrastructure configuration. Overseen directly by Equitus Corporation — the same firm securing U.S. Army and DHS systems.
Security Partner
Equitus Corporation is a defense-technology firm founded by Brigadier General Robert E. Guidry, U.S. Army (Ret.). Their clients include the U.S. Army, the Department of Homeland Security, Lockheed Martin, and IBM.
Their CTO, Michael Avina — formerly of Lockheed Martin and Thoughtworks — directly oversees Kaffeine's backend architecture: 7 production Rust microservices, HIPAA-compliant data design, and Zero-Trust security controls that mirror the standards applied to national security intelligence platforms.
"The same rigor we apply to national security intelligence platforms is the foundation we built Kaffeine's backend on. Insurance agencies — especially large FMOs — deserve the same protection as critical infrastructure."— Michael Avina, CTO, Equitus Corporation
BG Robert E. Guidry
Founder, U.S. Army (Ret.)
Michael Avina
CTO, ex-Lockheed Martin
U.S. Army / DHS
Federal Client Portfolio
Zero-Trust
Security Architecture Model
Enterprise FMO Commitments
About Equitus
The defense-tech firm behind Kaffeine's backend architecture.
ArcXA in Action
The semantic zero-loss migration engine moving legacy data into Kaffeine.
KGNN — Knowledge Graph Neural Network
How KGNN unifies siloed data into clean, AI-ready intelligence.
Kaffeine partners with Equitus Corporation — the defense-tech firm securing systems for the U.S. Army, DHS, and IBM — to bundle two enterprise solutions no other CRM offers: the KGNN knowledge graph engine and the ArcXA explainable migration layer. Both ship standard on every plan — no add-ons, no metering.
Knowledge Graph Engine
An autonomous graph platform that automatically ingests, cleans, and structures your fragmented data into a schema-less, AI-ready knowledge graph — fueling Rachel AI, Bean AI, and every analytics view with complete, contextualized data. Full provenance means every insight is traceable and explainable.
Explainable Migration
A mapping intelligence layer that sits above your existing stack — not another ETL tool. It uses hybrid AI to assign business meaning to source fields, builds a reusable ontology, and keeps a cryptographic audit chain. The result: zero-data-loss migration from any legacy platform — AgencyBloc, HawkSoft, AMS360, Salesforce, Applied Epic — that's audit-proven and explainable.
Every transformation ArcXA runs is captured at the rule and value level and sealed in a tamper-evident record. When an auditor asks where a number came from, the answer takes seconds — not a war room. It's the governance layer insurance agencies have never had during a CRM migration, and it's standard on every Kaffeine plan.
No Add-Ons. No Metering. No Extra Cost.
Enterprise FMOs can request a dedicated security briefing, penetration test results under NDA, and a custom BAA review with our compliance team.