Record-level encryption
Every record and every version of it is sealed with its own AES-256-GCM key; record keys live only inside the per-chunk key blocks.
Record-level encryption
Every record and every version of it is sealed with its own AES-256-GCM key; record keys live only inside the per-chunk key blocks.
Provable deletion
Deleted records drop out of reads at once, leave the key blocks at the weekly roll, and the old epoch keys are destroyed.
Two-person rule
Batch deletions, full exports, new identities and organisation activations wait for a second person’s passkey approval.
Verifiable audit
Key journals are hash chained and sealed with signed checkpoints; you run the verification yourself.