Your workspace.
Its own data boundary.
Your team’s work deserves a clear home and clear controls. Keep gives each workspace dedicated application resources on Cloudflare, with access scoped to the people and agents you authorize.
A separate home
for your workspace data.
Each Keep workspace is provisioned with its own Cloudflare D1 database, R2 storage bucket and tenant Worker. The Worker’s resource bindings point to that workspace’s database and files.
That separation gives your project records and uploaded artifacts a tenant-specific storage boundary. Shared Keep services handle identity, routing, administration and operational telemetry.
“Dedicated” describes these application resources. They run on Cloudflare’s shared infrastructure; it does not mean a dedicated physical server or a separate Cloudflare account.
The right access. For people and agents.
- 01
Membership and project permissions
Workspace membership and project roles determine access to records and actions. Connecting an agent does not make it a workspace administrator; its requests remain subject to the user’s permissions.
- 02
Connections you can revoke
AI clients connect through an authorization flow. Keep checks current workspace membership on agent requests, and you can revoke a connection when it is no longer needed.
Authorized tools can return project information to your connected AI client. That provider’s handling of the returned data is governed by your settings and agreement with it.
- 03
Deliberate sharing
Artifact share links can carry a password and expiry, and can be revoked. A public share link lets its recipient read the shared artifact without a Keep login. Embedded Google Docs retain their Google permissions.
Explore document sharing - 04
Encryption for stored data
Cloudflare documents automatic AES-256 encryption at rest for D1 databases and R2 objects, with keys managed by Cloudflare. Its documentation also describes TLS protection for D1 transfers and client connections to R2.
Built on Cloudflare.
Designed around your workspace.
Keep brings compute and storage together on Cloudflare’s developer platform. The tenant model uses these services together, with resource bindings configured for each workspace.
Workers for Platforms
Runs the tenant Worker in Cloudflare’s isolated execution environment.
About Workers for PlatformsD1
Stores the workspace’s structured project records in its dedicated database.
About D1R2
Stores documents, uploaded files and other artifact content in its dedicated bucket.
About R2
Resilience underneath.
Recovery within reach.
Keep runs on Cloudflare’s Workers platform and managed storage services. Application availability also depends on Keep, authentication and the underlying services; an incident in a dependency can affect access.
Keep is currently in private beta. A Keep-specific uptime SLA is not published. Cloudflare’s service commitments and status describe its platform, rather than end-to-end Keep availability.
View Cloudflare’s platform statusDurable object storage
R2 uses replication or erasure coding and storage across multiple data centers within a region to protect against hardware failures. Durability protects stored data; it is a different measure from service uptime.
How R2 protects stored objectsA way to recover
Keep’s recycle bin retains deleted records for 30 days unless an authorized owner permanently deletes them earlier.
Separately, D1 provides infrastructure-level point-in-time recovery through Time Travel, with retention depending on the Cloudflare plan. This is distinct from Keep’s record-level restore.
D1 Time Travel documentation
Need a closer look?
Ask about tenancy, data handling or availability before bringing your team’s work into Keep.
