Security Architecture, Encryption & Compliance
How Vyntech Cloud isolates tenant workloads, encrypts cluster credentials with AES-256-GCM, and satisfies sovereign Australian compliance standards.
1. Encrypted Kubeconfig Vault
All Kubernetes cluster connection credentials and TLS certificates are encrypted at rest using AES-256-GCM envelope encryption before persistence in the vyntech_cloud database.
2. Namespace & Network Policy Isolation
Tenant workloads run inside dedicated namespaces hardened with default-deny ingress/egress network policies, non-root container user enforcement, and read-only root filesystems where specified.
3. Essential Eight & SOC 2 Compliance
Meets ASD Essential Eight ML3 guidelines for application whitelisting, administrative privilege restriction, multi-factor authentication, and daily encrypted volume backups.