Security & Risk Review
In ReviewThreat model, key management, dependency posture, and open remediation items.
- CATEGORY
- Security
- VERSION
- 1.0
- UPDATED
- Jul 23, 2026
- ACCESS
- Extended review
What is protected, how, and what remains open.
The review covers the issuance path, the signing path, key custody and rotation, and the dependency surface. Each open risk is listed with an owner and an intended remediation rather than a reassurance.
Because verification is local, customer data does not leave the customer's deployment. The processing boundary, retention rules and sub-processor list are stated in the privacy and data handling policy.
INTERNAL REVIEW ONLY — No third-party penetration test or security certification has been completed. Open items are current as of the review's effective date.
Threat model, key management, dependency posture, and open remediation items.
What data is processed, where it stays, and how demo data is isolated.