Security
Key management, reviewable audit events, and data minimization by default.
Key management
Public keys are used for verification. Signing keys are managed server-side with rotation support.
Audit events
Provenance events are append-only and support technical audit trails for customer review.
Data minimization
We store hashes and signed metadata only, never raw content.
Webhook integrity
Webhook deliveries are signed with HMAC for verification.