Shared responsibility & FAQ
Because Penfield runs in your environment, security is a shared model: you control the platform and perimeter; Penfield provides a hardened application that fits into your standards.
Shared responsibility
| Area | Customer | Penfield |
|---|---|---|
| Cloud account, subscription, and regions | ✅ | |
| Network (VPC/VNet, VPN, firewalls, WAF, private DNS) | ✅ | Guidance |
| Kubernetes / OpenShift cluster hardening and upgrades | ✅ | Guidance |
| Namespace, cluster RBAC for install/operate | ✅ | Recommended manifests / docs |
| TLS certificates and application DNS | ✅ | App serves HTTPS when TLS is terminated as you configure |
| Identity provider (Entra ID, AD FS) and MFA policies | ✅ | OIDC integration |
| Disk / PVC / storage encryption and key management | ✅ | Docs recommend encrypted storage |
| Backup and disaster recovery of volumes/databases | ✅ | Guidance |
| Application images, application RBAC, product security features | ✅ | |
| Secure SDLC, vulnerability management of the product | ✅ | |
| SOC 2 Type II for Penfield as an organization | ✅ | |
| ISO 27001 for Penfield as an organization | ✅ | |
| Penetration test reports (under NDA) | ✅ |
Common vendor risk questions
Does Penfield host our data?
No. Penfield is installed in your Kubernetes or OpenShift environment. Application data remains in your databases and volumes and is not sent to Penfield.
Is the application publicly accessible?
It is designed for private access (VPN or internal network). Public exposure is not required and is discouraged unless you explicitly choose that network design.
How do users authenticate?
Either:
- SSO with your IdP using OIDC (for example Microsoft Entra ID), or
- Local users, with optional MFA, managed inside Penfield.
Where is data stored, and is it encrypted?
- Stored in MongoDB and PostgreSQL running in your Kubernetes cluster by default.
- Data persists on PVCs backed by your storage.
- In transit: HTTPS/TLS for client access.
- At rest: via your encrypted disks / storage classes.
- Local passwords: Argon2id hashed.
Do we need to open the Kubernetes cluster to Penfield?
There is no default Penfield access to your Kubernetes cluster. Penfield gets access only if you install through the marketplace (where Penfield can manage the deployment), or if you grant access on your own Kubernetes cluster. Otherwise we have no access. The product can also be deployed and operated entirely by your team.
What compliance certifications does Penfield have?
- SOC 2 Type II
- ISO 27001
Certificates and detailed reports are available upon request under NDA.
What about penetration tests?
Penetration test reports can be shared with customers and prospects under NDA through your Penfield representative.
What do we install?
The Penfield application components into a dedicated namespace on your Kubernetes cluster, plus the supporting databases described in the product docs. You continue to operate the underlying Kubernetes cluster and network to your standards.
Can local accounts be removed?
Yes. Local users can be created or deleted by authorized Super Admins at any time. In SSO mode, access lifecycle is controlled in your IdP.
Where can operators find install guides?
In Product Docs, including requirements, deployment, SSO setup, and user management. For engineering security process overview, see the Secure SDLC guide.
What we share publicly vs under NDA
| Public (this Trust Center) | Available under NDA |
|---|---|
| Deployment and security model | Full SOC 2 Type II report |
| High-level architecture | ISO 27001 certificate package (as applicable) |
| Data storage and encryption summary | Penetration test report / summary |
| Identity options and RBAC overview | Deal-specific network diagrams if required |
| Shared responsibility and FAQ |
Contact
For security questionnaires, report requests, or architecture reviews, contact your Penfield account or security contact, or reach out via penfield.ai.