Security & Compliance

DoD-Grade Security.
Built for Insurance.

Kaffeine's security infrastructure is engineered by Equitus Corporation — a defense-technology firm whose clients include the U.S. Army, DHS, Lockheed Martin, and IBM. Every control is designed to protect your PHI, your downline, and your carriers.

7

Production Rust Microservices

55+

Database Tables

110+

Optimized Indexes

5

Concentric Defense Layers

AES-256

Encryption Standard

TLS 1.3

Transport Security

7-Year

Audit Log Retention

< 15 min

Critical MTTR

Defense in Depth

5 Concentric Security Layers

No single point of failure. Each layer independently blocks a class of threats — and continuously monitors for drift in the others.

01

Identity & Access Management

  • Multi-factor authentication (MFA) enforced for all users
  • Role-based access control (RBAC) with least-privilege defaults
  • SSO via SAML 2.0 / OAuth 2.0 for enterprise FMOs
  • Session token expiry and forced re-authentication on sensitive operations
  • Audit log of every login, role change, and data export
02

Network & Edge Protection

  • TLS 1.3 in transit across all API endpoints and webhooks
  • WAF (Web Application Firewall) with DDoS mitigation at the edge
  • IP allowlisting available for FMO enterprise accounts
  • VPC network isolation — no public access to backend services
  • Automated rate limiting and bot detection on all endpoints
03

Data Encryption & PHI Protection

  • AES-256 encryption at rest via AWS KMS (Customer-Managed Keys available)
  • PHI tokenization — raw identifiers never stored in application tables
  • Column-level encryption for SSN, DOB, and policy identifiers
  • Separate KMS key per tenant — no cross-tenant key reuse
  • Encrypted backups with 90-day point-in-time recovery
04

Application-Level Controls

  • Row-Level Security (RLS) enforced at the database layer — not the application layer
  • Multi-tenant isolation: no query can cross organizational boundaries
  • Parameterized queries throughout — zero SQL injection surface
  • Input validation and output encoding on all user-supplied data
  • OWASP Top 10 mitigations built into CI/CD pipeline
05

Detection & Continuous Response

  • Automated red-team testing simulates API abuse, injection, and privilege escalation
  • Anomaly detection on data access patterns — alerts on bulk exports or off-hours queries
  • 6-step tamper-proof audit trail with cryptographic hash chain
  • Automated threat remediation with < 15-min MTTR for critical findings
  • SOC 2 Type II evidence continuously collected and archived

Authorization & Decision Enforcement

Not Just Who Can Enter —
What Every Identity Can Do Inside.

Traditional CRM security is organized around Login → Role → Application Access. Kaffeine is designed around a continuously enforced decision chain that controls what every human, service, integration, workflow, and AI agent can do after they are inside — and explains and audits every consequential decision.

Traditional CRM Security

LoginRoleApplication Access

This model protects who can enter the CRM — then grants broad application-level permissions. Actions performed inside are not individually authorized, context is not evaluated per request, and decisions are not explained.

Kaffeine High-Assurance Environment

IdentityAuthentication AssuranceContextResourceActionPolicyDecisionEnforcementAudit

CRM operations execute inside a continuously enforced security perimeter. Not a SaaS app protected by controls — a high-assurance information environment where every identity, capability, action, decision, and transaction is bounded, explained, and traced.

Every identity is known.

Every privileged capability can be bounded.

Every sensitive action can require explicit authority.

Every important decision can be explained.

Every consequential transaction can be traced.

What this means in practice: humans, service accounts, third-party integrations, automated workflows, and AI agents are all treated as identities. Each is authenticated, assigned bounded capabilities, and evaluated against policy on every sensitive action — with the decision and its reasoning written to a tamper-proof audit trail. Nothing inside Kaffeine is trusted by default.

Compliance

Built to the Highest Standards

We don't bolt compliance on at the end. Every control is designed into the architecture from day one.

Fully Compliant

HIPAA § 164.312(b)

Audit Controls

6-step immutable audit trail with tamper-proof hash chain. All PHI access, modification, and export events are logged, timestamped, and retained for 7 years in compliance with HIPAA's audit control requirements.

Fully Compliant

HIPAA § 164.312(a)(2)

Automatic Logoff & Auth

Session inactivity timeout enforced across all user tiers. Emergency access procedures documented and tested. Unique user identification for all PHI access — shared credentials are architecturally prevented.

Fully Compliant

HIPAA § 164.312(e)(2)

Encryption & Decryption

All ePHI encrypted with AES-256 at rest and TLS 1.3 in transit. PHI tokenized at ingestion — cleartext health data is never stored in application tables or logs.

Evidence-Ready

SOC 2 Type II

Trust Services Criteria

Security, availability, and confidentiality controls continuously collected and evidence-ready. Automated control monitoring ensures drift is detected and remediated before audit cycles.

Aligned

NIST 800-53

Federal Security Controls

Architecture aligned to NIST 800-53 control families including AC (Access Control), AU (Audit), SC (System & Communications), and SI (System Integrity) — the same framework used by federal agencies.

Architecture Aligned

DoD STIGs

Defense Information Systems

Security Technical Implementation Guides (STIGs) applied to infrastructure configuration. Overseen directly by Equitus Corporation — the same firm securing U.S. Army and DHS systems.

Security Partner

Powered by
Equitus Corporation

Equitus Corporation is a defense-technology firm founded by Brigadier General Robert E. Guidry, U.S. Army (Ret.). Their clients include the U.S. Army, the Department of Homeland Security, Lockheed Martin, and IBM.

Their CTO, Michael Avina — formerly of Lockheed Martin and Thoughtworks — directly oversees Kaffeine's backend architecture: 7 production Rust microservices, HIPAA-compliant data design, and Zero-Trust security controls that mirror the standards applied to national security intelligence platforms.

"The same rigor we apply to national security intelligence platforms is the foundation we built Kaffeine's backend on. Insurance agencies — especially large FMOs — deserve the same protection as critical infrastructure."— Michael Avina, CTO, Equitus Corporation

BG Robert E. Guidry

Founder, U.S. Army (Ret.)

Michael Avina

CTO, ex-Lockheed Martin

U.S. Army / DHS

Federal Client Portfolio

Zero-Trust

Security Architecture Model

Enterprise FMO Commitments

  • Business Associate Agreement (BAA) executed at account activation
  • Dedicated security review available for enterprise FMOs (500+ agents)
  • Custom data retention policies configurable per organization
  • Penetration test results available under NDA upon request
  • Incident response runbook shared with enterprise customers
  • Quarterly security briefings for FMO compliance teams

About Equitus

The defense-tech firm behind Kaffeine's backend architecture.

ArcXA in Action

The semantic zero-loss migration engine moving legacy data into Kaffeine.

KGNN — Knowledge Graph Neural Network

How KGNN unifies siloed data into clean, AI-ready intelligence.

Powered by Equitus Corporation

Enterprise Data Intelligence.
Included for Every User.

Kaffeine partners with Equitus Corporation — the defense-tech firm securing systems for the U.S. Army, DHS, and IBM — to bundle two enterprise solutions no other CRM offers: the KGNN knowledge graph engine and the ArcXA explainable migration layer. Both ship standard on every plan — no add-ons, no metering.

Knowledge Graph Engine

KGNN

An autonomous graph platform that automatically ingests, cleans, and structures your fragmented data into a schema-less, AI-ready knowledge graph — fueling Rachel AI, Bean AI, and every analytics view with complete, contextualized data. Full provenance means every insight is traceable and explainable.

  • Automated ETL & semantic mapping — no manual schema design
  • Self-generating, schema-less knowledge graph from any dataset
  • Full data provenance, traceability & explainability for AI
  • Unifies CRM, carrier, lead & commission data into one layer
  • Cuts data-prep time by up to 80%

Explainable Migration

ArcXA

A mapping intelligence layer that sits above your existing stack — not another ETL tool. It uses hybrid AI to assign business meaning to source fields, builds a reusable ontology, and keeps a cryptographic audit chain. The result: zero-data-loss migration from any legacy platform — AgencyBloc, HawkSoft, AMS360, Salesforce, Applied Epic — that's audit-proven and explainable.

  • Hybrid AI — 60% statistical + 40% semantic reasoning
  • Ontology reusable across every migration — knowledge compounds
  • Cryptographic, tamper-evident audit chain (HIPAA & SOX)
  • Rule-level transformation lineage — trace any field in seconds
  • Early anomaly detection before go-live, not after

Cryptographic audit chain — built for HIPAA & SOX

Every transformation ArcXA runs is captured at the rule and value level and sealed in a tamper-evident record. When an auditor asks where a number came from, the answer takes seconds — not a war room. It's the governance layer insurance agencies have never had during a CRM migration, and it's standard on every Kaffeine plan.

No Add-Ons. No Metering. No Extra Cost.

KGNN + ArcXA are included on every plan.

AgentAgencyFMO / IMOCombined

Ready to Run a Security Review?

Enterprise FMOs can request a dedicated security briefing, penetration test results under NDA, and a custom BAA review with our compliance team.