Skip to main content
Citadel Exchange
TrustPricingSign inGet started

Trust centre

Security you can inspect

How Citadel Exchange protects client exchanges: encryption design, sub-processors, live availability, and the status of independent assurance—without inventing certifications we do not have yet.

Encryption

Citadel Exchange encrypts room messages and files in your browser before they reach our servers. Operators can store ciphertext and metadata; they cannot read room plaintext without customer-held keys.

End-to-end

  • Messages and file contents in exchange rooms
  • Room encryption keys (wrapped per member)
  • Your identity private key (wrapped on your device)

Visible to the server

  • Account email, display name, organization membership
  • Room membership, roles, and invitation state
  • File sizes, timestamps, and event types
  • Blind-index search tokens (not plaintext keywords)
  • Ciphertext blobs and related metadata

Metadata supports access control, retention, and audit. It is not end-to-end encrypted.

Key hierarchy

LayerMechanism
ContentAES-256-GCM, fresh IV per payload
Room keysECDH P-256 wraps of a shared AES room key
Identity wrapPBKDF2-HMAC-SHA256 (600,000 iterations) → AES wrap
RecoveryBIP-39 12-word phrase (optional second wrap)
SSO staffVault passphrase (not the IdP password) + required recovery phrase
TransportTLS 1.2+

There is no operator key escrow. Losing both the vault secret and recovery phrase means the data cannot be recovered by Citadel.

Membership removal

Removed members lose room membership and wrapped keys. Rooms are flagged for key epoch rotation so remaining members can issue a new room key for future ciphertext.

Sub-processors

Sub-processors

These categories match the Data Processing Agreement. Production vendor names must be finalized before counsel sign-off.

  • Infrastructure host — application and Postgres
  • Object storage (MinIO or S3-compatible) — encrypted file objects
  • Stripe — payments and billing portal
  • Transactional email provider — invitations and security alerts
  • Error / uptime monitoring (if enabled) — operational telemetry

Replace placeholder vendors in the DPA with your production choices before relying on this list in a deal.

Read the full DPA sub-processor section →

Availability

Availability

Public health probe of the API, metadata store, and scheduled jobs. External uptime monitors should target the same endpoint.

Major incident

checked —

Open the full status page →

Independent assurance

Independent assurance

External penetration testing and cryptographic design review are part of our launch gates. Summaries will appear here when engagements complete; until then, reports are available to qualified buyers under NDA.

Penetration test

In progress

Engagement brief ready; external test not yet complete. Critical findings will be fixed before public launch.

Cryptographic design review

In progress

Review brief ready for an independent cryptographer. This page’s crypto summary reflects the shipped design, not a third-party attestation.

Request reports under NDA

Uses the security disclosure address. Replace the placeholder mailbox before public launch.

Compliance program

Compliance program

We maintain SOC 2– and ISO 27001–aligned policies, control mapping, and admin attestation inside the product. Formal Type II / certification artifacts are not published until an auditor issues them.

  • SOC 2 Type II — program in place; observation window / auditor not complete
  • ISO/IEC 27001 — control mapping maintained; certification not yet issued
  • Policies for access control, crypto, acceptable use, and incident response available to customers under NDA
Contact sales for the security pack →

Responsible disclosure

Report authentication, isolation, or key-handling issues through our security contact. Coordinated disclosure: we aim to acknowledge within two business days.