Thanks to visit codestin.com
Credit goes to securelay.com

Trust Center

Inspect the controls. Verify the evidence.

Security should survive more than a sales call. Review the product boundaries, evidence available from protected operations, and deployment checks required in each customer environment.

Evidence firstPublic statements are grounded in tests, deployed proof, and documented residuals.
Security model

The boundaries we design and test.

Data boundary

Applications use tokens while sensitive values remain encrypted in the vault.

Decision boundary

The service evaluates policy, consent, purpose, role, scope, and operational gates before disclosure.

Key boundary

Tenant-scoped key paths support BYOK, rotation, revocation, and cryptographic erasure patterns.

Evidence boundary

Audit entries are chained and signed; exported bundles can be checked away from the running system.

Failure boundary

Protected operations fail closed when required policy, durable state, keys, or dependencies cannot be enforced.

Operator boundary

Administrative routes and runtime organization controls are authenticated, authorized, and audited.

Evidence model

Separate product proof from environment proof.

A product test does not prove a customer deployment. We review both evidence sets and keep residual risks explicit.

Product evidence

  • Offline-verifiable audit bundles
  • Disclosure, denial, and deletion receipts
  • Consent-bound access and withdrawal denial
  • Crypto-shred subject erasure paths
  • AI and MCP de-identification paths
  • Tenant isolation and key revocation tests

Environment evidence

  • Network and workload-identity enforcement
  • Customer key-management configuration
  • Backup, restore, and disaster-recovery tests
  • Measured throughput and capacity limits
  • Monitoring, incident, and resilience exercises
Coordinated disclosure

Found a security issue?

Email a clear reproduction to [email protected]. Do not access another customer’s data, disrupt availability, or publish an uncoordinated exploit. We will acknowledge and triage reports in good faith.

Preferred report
  • Impact and affected surface
  • Step-by-step reproduction
  • Logs or request IDs without sensitive data
  • Suggested remediation, if known