Security Architecture
Security-by-design: signed, fail-closed, PII encrypted at rest, only commitments on-chain, and quantum-resistant channels.
What it does
The Security Architecture is security-by-design. Decisions and evidence are Ed25519-signed; the platform fails closed; PII is encrypted at rest (AES-256-GCM) while only commitments — never raw personal data — go on-chain; and forward-secret, hybrid post-quantum channels protect the wire. It is the zero-trust foundation under every other engine — and prefer to run it yourself? It's self-hostable; see the Deployment Architecture.
Inside Security Architecture
The core functions this engine provides across the Trust Fabric.
Security Architecture composes with the Trust Fabric
Every engine is independently useful and interoperates through one API-first Trust Fabric — so identity, evidence, policy, risk and certification stay consistent across your AI estate.
Related engines
Deployment Architecture
Runs on Hedera (testnet or mainnet), self-hostable, with configurable, sovereign HCS topics.
- Hedera testnet / mainnet
- Self-hostable / sovereign
- Configurable HCS topics
- Cloud / on-prem / federated
Trust Fabric
The substrate that links identity, policy, evidence and the trust index into one consistent, on-chain view.
- Deterministic policy-core
- Identity (DIDs)
- Signed evidence on Hedera
- The Trust Index
Identity Engine
Issues each agent a verifiable, self-certifying DID and proves control of its key — the root every other engine trusts.
- did:hedera / did:key
- Key proof (verify-key / BYOK)
- Public DID resolver
- HCS registry anchoring
See Security Architecture in action
Book a demo and see how the platform establishes trust across your AI systems.
