TLS 1.3 only, HSTS preloaded, no legacy cipher suites.
AES-256 on all volumes; ledger segments separately keyed.
Your KMS on Compliance and Sovereign; Provena KMS otherwise.
SSO with SAML, enforced 2FA, role separation for signing.
Every signing and admin action, append-only, exportable.
Annual third-party test; last report April 2026, two medium findings closed.
Controls implemented and documented; certification audit Q1 2027.
Not started. We will say so until it is.
Private programme with 11 researchers; public programme planned.
Asset bytes are the sensitive part, and in Cloud they are processed in memory and discarded. What persists is the manifest, the hash and the ledger entry.
No US-based sub-processor is in the path of asset data. Changes are announced 30 days in advance.