TRUST CENTER · v.2026.05

We did the hard work before legal asked.

A trust posture designed for security teams, compliance officers, and platform reviewers — not for marketing pages. What follows is what they need to read.

AUDIT
Signed.
Sequenced.

Per-operation ed25519. Append-only chain. Locally verifiable.

KEYS
Yours.
Always.

Customer-managed keys on Enterprise. HSM-backed. Rotatable.

DATA
Where
you say.

EU, US, IN regions today. Any region on request.

SELF-HOST
Air-gapped
option.

Run the control plane inside your network. Identical reviewer flow.

COMPLIANCE

Mapped to the standards your reviewer cares about.

Status today. Roadmap stated, not implied. The mapping documents are available under NDA.

StandardStatusAudit cadenceMapping doc
SOC 2 Type IIcertifiedAnnualAvailable under NDA
ISO 27001certifiedAnnualAvailable under NDA
ISO 27701 (privacy)certifiedAnnualAvailable under NDA
GDPR (EU)compliantContinuousPublic summary
HIPAA (US healthcare)BAA availableContinuousBAA on request
PCI-DSS scope reductionguidanceArchitecture briefing
DORA (EU financial)alignedContinuousAvailable under NDA
FedRAMP Moderatein processQ4 2026 (planned)
AUDIT POSTURE

A chain you can verify without us in the room.

Audit on Ejenix is not a logging system. It is a per-operation signed, append-only record, designed to be verifiable locally with an open-source verifier we publish.

What is recorded

  • Every patch authoring, publication, promotion, hold, override, and rollback
  • Every cohort definition, version, retirement
  • Every policy gate evaluation and outcome
  • Every reviewer-packet generation
  • Every key usage with fingerprint and signer identity

What is not recorded

  • End-user device identifiers (we cohort on hashes, not IDs)
  • End-user content or PII
  • Source code (the patch artifact is referenced by hash, not stored as code)
SIGNED RECORD · GENESIS → CURRENT
2023-04-01 · GENESIS
Chain initialized · root hash sealed
2024 · 4,118 ops
Year one · zero broken segments
2025 · 18,907 ops
Year two · zero broken segments
2026 (YTD) · 11,402 ops
Year three · zero broken segments
$ ejenix verify --since genesis  →  OK · 34,427 ops · chain unbroken
REVIEWER PACKET

A bundle reviewers actually open.

Whatever the scope — one patch, one quarter, one incident — Ejenix produces a signed bundle your auditor can verify locally. We publish the verifier; we do not need to be involved in the review.

What's inside

  • manifest.json — scope, identities, key fingerprints
  • chain.log — full operation chain with signatures
  • cohorts.yml — cohort predicates & reach estimates
  • policy.eval — gate evaluations & outcomes
  • perf.posture — cold-start, binary, runtime budgets
  • signatures/ — detached per-op signatures

Total size of a typical quarter: under 5 MB. Verification time: under 2 seconds on a laptop.

What we will brief your team on

  • Trust posture & threat model
  • Signed-audit format & verifier walk-through
  • Key custody & rotation
  • Data residency & tenancy options
  • Eligibility gating policy
  • Incident-response process

For deeper architectural questions, see the private briefing — these stay under technical NDA.

THE OUTER WALL

What we will not publish on a website.

Trust does not require us to reveal the engine. The reviewer packet is enough for due diligence; the architecture briefing is enough for technical review.

PUBLIC

What we publish

  • Trust posture & threat model
  • Signed-audit specification
  • Public-safe verifier (open source)
  • Compliance summaries
  • Workflow & operational documentation
NDA
PRIVATE

What we brief, under NDA

  • Engine internals
  • Compiler & runtime mechanism
  • Artifact format details
  • Execution-path naming
  • Available to your security & platform reviewers only.
PRIVATE BRIEFING

Bring the team that has to sign off.

CISO, head of compliance, platform reviewer. One 60-minute session, NDA up front, technical answers without marketing language. We do this twice a week.

  • Architecture walk-through under NDA
  • Reviewer-packet verification, live
  • Key-custody & rotation walkthrough
  • Threat-model Q&A
  • Compliance mapping for your context
REQUEST BRIEFING

Schedule a 60-minute session

We can prove this works. We are not publishing the moat.

Request private briefing Talk to engineering