For your IT and risk team.

Short answers to the questions a security review usually starts with. If your team needs more detail, write to us and we will go through it with them: info@subtractsoftware.com

Where is our data?

With you. We never hold it.

ByteCustodian runs inside your own AWS account, or on your own hardware. Every install is single-tenant. On AWS, the storage, the database and the platform all sit in your account, under your access rules. On your own hardware, they sit on your machines. We have no access to either unless you give it to us.

The platform has no usage meter, so it has nothing to report back to us, and it does not.

Who can see what?

The rules are enforced where the query runs.

Row rules and column masks are built into what each person is able to query. They are not a filter applied afterwards. A person with no grant sees zero rows, not an error.

Anything an analyst writes works on the value after it is masked, so no clever expression gets the real one back.

How do people sign in?

Through your identity provider, with your groups.

Sign-in uses OpenID Connect, the standard. There are setup guides for Microsoft Entra ID, Okta, Auth0, Keycloak, AWS Cognito and Ping Identity.

Your provider says who a person is and which groups they belong to. Permissions attach to groups only, never to a person. Service logins for automation go through the same path.

What is recorded?

Every action, in your own database.

Sign-ins, queries, changes to access and every administrator action go to an audit trail. It lives in your database, not ours.

One thing said plainly: no platform can defend against its own administrator. Ours records what they did.

How are credentials handled?

Scoped to the user. None in analysis code.

Every credential is scoped to the user it was issued for. Analysis code is untrusted code, and we treat it that way: it holds zero credentials.

How is it tested?

A written threat model, and an attack suite that runs before every release.

The threat model says what we defend against and, just as plainly, what we do not. The attack suite tries to break the rules on this page.

On 31 August 2026 we ran our own penetration test against a deployed install, signed in as four different kinds of user. It found four things. None reached governed data, and all four are fixed.

Not done yet: an independent penetration test. It is planned before our first regulated customer.

How does data get in?

You put it there, and you review it first.

Upload a file in the browser, or stage large files in your own storage with any S3 client. The platform checks the file and shows you what would go wrong before it happens. It loads only when you launch it.

Adding, correcting and removing rows go through the same reviewed step.

Who do we talk to?

The people who built it.

We are a small company, and we do not hide it. You deal directly with the engineers who wrote the product, and forty free hours of our time come with every install.

Our founder has thirty years in software, and rose to R&D Director building the risk, governance and compliance platforms that some of the largest banks and insurers run on. His note is on the About page.

Send us their questions.

Pass this page to your security team. We will answer what they ask in writing. Under a confidentiality agreement, we will also walk them through the threat model and show the attack suite running.

Start the security review: info@subtractsoftware.com