TRUST & SECURITY

Your workspace.
Its own data boundary.

Your team’s work deserves a clear home and clear controls. Keep gives each workspace dedicated application resources on Cloudflare, with access scoped to the people and agents you authorize.

Dedicated databaseSeparate file storageScoped access
Keep’s shared servicesIdentity · routing · platform administration
YOUR WORKSPACE
Tenant WorkerBound to your workspace’s resources
D1 databaseProject records
R2 bucketDocuments & files
Simplified view of Keep’s tenant resources on Cloudflare.
01 / DEDICATED TENANCY

A separate home
for your workspace data.

Each Keep workspace is provisioned with its own Cloudflare D1 database, R2 storage bucket and tenant Worker. The Worker’s resource bindings point to that workspace’s database and files.

That separation gives your project records and uploaded artifacts a tenant-specific storage boundary. Shared Keep services handle identity, routing, administration and operational telemetry.

“Dedicated” describes these application resources. They run on Cloudflare’s shared infrastructure; it does not mean a dedicated physical server or a separate Cloudflare account.

02 / SECURITY & ACCESS

The right access. For people and agents.

  1. 01

    Membership and project permissions

    Workspace membership and project roles determine access to records and actions. Connecting an agent does not make it a workspace administrator; its requests remain subject to the user’s permissions.

  2. 02

    Connections you can revoke

    AI clients connect through an authorization flow. Keep checks current workspace membership on agent requests, and you can revoke a connection when it is no longer needed.

    Authorized tools can return project information to your connected AI client. That provider’s handling of the returned data is governed by your settings and agreement with it.

  3. 03

    Deliberate sharing

    Artifact share links can carry a password and expiry, and can be revoked. A public share link lets its recipient read the shared artifact without a Keep login. Embedded Google Docs retain their Google permissions.

    Explore document sharing
  4. 04

    Encryption for stored data

    Cloudflare documents automatic AES-256 encryption at rest for D1 databases and R2 objects, with keys managed by Cloudflare. Its documentation also describes TLS protection for D1 transfers and client connections to R2.

03 / THE CLOUDFLARE FOUNDATION

Built on Cloudflare.
Designed around your workspace.

Keep brings compute and storage together on Cloudflare’s developer platform. The tenant model uses these services together, with resource bindings configured for each workspace.

  • Workers for Platforms

    Runs the tenant Worker in Cloudflare’s isolated execution environment.

    About Workers for Platforms
  • D1

    Stores the workspace’s structured project records in its dedicated database.

    About D1
  • R2

    Stores documents, uploaded files and other artifact content in its dedicated bucket.

    About R2
Cloudflare’s platform security and compliance materials describe Cloudflare’s services. They are not a separate certification of Keep.Visit Cloudflare’s Trust Hub
04 / AVAILABILITY & RECOVERY

Resilience underneath.
Recovery within reach.

Keep runs on Cloudflare’s Workers platform and managed storage services. Application availability also depends on Keep, authentication and the underlying services; an incident in a dependency can affect access.

Keep is currently in private beta. A Keep-specific uptime SLA is not published. Cloudflare’s service commitments and status describe its platform, rather than end-to-end Keep availability.

View Cloudflare’s platform status
  • Durable object storage

    R2 uses replication or erasure coding and storage across multiple data centers within a region to protect against hardware failures. Durability protects stored data; it is a different measure from service uptime.

    How R2 protects stored objects
  • A way to recover

    Keep’s recycle bin retains deleted records for 30 days unless an authorized owner permanently deletes them earlier.

    Separately, D1 provides infrastructure-level point-in-time recovery through Time Travel, with retention depending on the Cloudflare plan. This is distinct from Keep’s record-level restore.

    D1 Time Travel documentation
LET’S TALK ABOUT YOUR REQUIREMENTS

Need a closer look?

Ask about tenancy, data handling or availability before bringing your team’s work into Keep.

Contact the Keep team
Information reviewed 21 September 2026.Read our privacy information