Audit and verification
Every important document in Reindeer is signed so that you can verify it without trusting the server. You run the verification yourself: with reindeerctl, or in the console inside your browser.
Key journals
Section titled “Key journals”Each custodian (primary and DR) writes every key use to a hash-chained journal. The chain is sealed by checkpoints signed with the Ed25519 audit key on the HSM token. Removing or changing an entry breaks the chain.
reindeerctl audit journal primary -pin <primary audit key>reindeerctl audit journal dr -pin <DR audit key>Receipts and erasure certificates
Section titled “Receipts and erasure certificates”- Every commit returns an EdDSA-signed receipt with the upload result (records, chunks and batches).
- Every destruction produces an erasure certificate signed by the receipts key. See Deletion and erasure.
Pinning the keys
Section titled “Pinning the keys”When you first trust a cell, fetch its public keys and keep them outside the cell:
reindeerctl audit keysPass these keys with -pin on later checks. Without -pin the tools only show that the documents agree with the key the same server presented. The console pins the keys in the browser on first use; it flags a changed key and never reports it as verified.
Access log
Section titled “Access log”/v1/audit/events records who did what and when: every change, every refused request and sensitive reads. Request bodies and clear ids never enter it.