Security

Evidence access is deny-default, purpose-bound, and auditable.

The reference architecture isolates connector credentials, policy evaluation, evidence storage, and signing responsibilities across tenant boundaries.

Reference architecture · controls planned
01

Credential isolation

Use scoped, short-lived credentials and customer-controlled connector deployment where required.

02

Encryption + keys

Protect evidence in transit and at rest, with dedicated or customer-managed key options by deployment.

03

Audit export

Export signed access, resolution, verification, replay, and administration records.

Current limitationCertifications and production controls are not claimed until independently verified.
Inspect a Bundle