Preview honesty. Local / customer-controlled trust model. Not multi-tenant hostile enterprise yet. No formal third-party audit.
Assets we care about
- Vault plaintext and passphrases
- Evidence package integrity and authenticity
- Integrity of this public site (signed manifest)
- Gateway data plane under customer control
In scope threats (examples)
- Passive network observer of vault files without passphrase
- Tampering with package bytes after seal
- Swapping marketing site HTML after integrity signing
- Unauthorized ingest if gateway token leaks (customer ops issue)
Out of scope / not claimed
- Endpoint malware that steals passphrase as you type it
- Global compromise of customer gateway host
- KMS/HSM-backed enterprise key lifecycle (not shipped)
- “Whole company certified secure” via a badge image
Current limitations
- No formal third-party audit
- No KMS/HSM product
- No formal rotation/revocation product
- Gateway pilot may run in shadow mode (records, does not control ops)
Security page · Audit status · Site integrity