Skip to content

Audit and verification

Every important document in Reindeer is signed so that you can verify it without trusting the server. You run the verification yourself: with reindeerctl, or in the console inside your browser.

Each custodian (primary and DR) writes every key use to a hash-chained journal. The chain is sealed by checkpoints signed with the Ed25519 audit key on the HSM token. Removing or changing an entry breaks the chain.

Terminal window
reindeerctl audit journal primary -pin <primary audit key>
reindeerctl audit journal dr -pin <DR audit key>
  • Every commit returns an EdDSA-signed receipt with the upload result (records, chunks and batches).
  • Every destruction produces an erasure certificate signed by the receipts key. See Deletion and erasure.

When you first trust a cell, fetch its public keys and keep them outside the cell:

Terminal window
reindeerctl audit keys

Pass these keys with -pin on later checks. Without -pin the tools only show that the documents agree with the key the same server presented. The console pins the keys in the browser on first use; it flags a changed key and never reports it as verified.

/v1/audit/events records who did what and when: every change, every refused request and sensitive reads. Request bodies and clear ids never enter it.