Product evidence
- Offline-verifiable audit bundles
- Disclosure, denial, and deletion receipts
- Consent-bound access and withdrawal denial
- Crypto-shred subject erasure paths
- AI and MCP de-identification paths
- Tenant isolation and key revocation tests
Security should survive more than a sales call. Review the product boundaries, evidence available from protected operations, and deployment checks required in each customer environment.
Applications use tokens while sensitive values remain encrypted in the vault.
The service evaluates policy, consent, purpose, role, scope, and operational gates before disclosure.
Tenant-scoped key paths support BYOK, rotation, revocation, and cryptographic erasure patterns.
Audit entries are chained and signed; exported bundles can be checked away from the running system.
Protected operations fail closed when required policy, durable state, keys, or dependencies cannot be enforced.
Administrative routes and runtime organization controls are authenticated, authorized, and audited.
A product test does not prove a customer deployment. We review both evidence sets and keep residual risks explicit.
Email a clear reproduction to [email protected]. Do not access another customer’s data, disrupt availability, or publish an uncoordinated exploit. We will acknowledge and triage reports in good faith.