You should not have to trust us.
Notaree custodies other companies’ evidence. That makes security the product rather than a feature of it. This page states our posture, including the parts that are not finished.
Every bundle verifies without us.
An evidence bundle is checked by an open-source verifier that makes no network calls and trusts no server — in TypeScript, or in pure Python with zero dependencies, so an auditor can run it against a stock interpreter. Two independent implementations reproduce a committed conformance corpus byte for byte.
If our infrastructure were entirely compromised, a verifier would still detect any alteration of existing evidence.
Implemented today.
Tamper-evident by construction
Each record commits to the hash of the one before it. Batches are committed to an RFC 6962 Merkle root and signed in a hardware key store, where the private key cannot be exported.
Tenant isolation in the database
Postgres row-level security is FORCE-enabled per table and is the enforcement boundary — not application filtering. A cross-tenant test runs in CI against a real Postgres on every push.
Redaction before persistence
PII is removed in the ingest path before anything is written, fails closed, and records its ruleset version. Hash-only mode chains the payload hash without storing the payload at all.
No customer provider keys
We never store your LLM provider API keys. Holding them would make us a far more attractive target for no product benefit.
Append-only
The database forbids deletion of chain records. Retention expiry is an event, not a silent removal. Signed roots are mirrored to immutable object storage.
Agent behaviour, watched twice
Actions are scored against a policy you declare — once in-process where a run can still be halted, and again after the record leaves your process, where your agent cannot switch it off.
Stated plainly, because you would find out anyway.
- We cannot attest to what was never sent. We record faithfully what reaches us. An agent that routes around its own instrumentation is invisible to any SDK-level recorder, ours included — this is a documented technique, not a hypothetical.
- We are not a sandbox, a WAF, or an EDR. Detection narrows the window and raises the cost of an incident. It does not prevent one, and we will not claim a percentage.
- A compromise of our signing key would let an attacker forge new attestations going forward — but not silently alter existing anchored evidence. Hardware custody and signed key rotation bound this.
- We hold no SOC 2 today. It is on the roadmap and we will not claim it until it is achieved.
- No external cryptographic review yet. Correctness currently rests on 100% branch coverage of the integrity core, property-based tests, a committed conformance corpus, and two independent implementations that agree. A third-party review is funded from early revenue.
Tell us, and we will credit you.
Email eckoeyo@gmail.com with details and a proof of concept if you have one. We aim to acknowledge within two business days and ask for a reasonable window to remediate before public disclosure. We do not run a paid bounty yet; we will credit reporters who want to be named.
Machine-readable contact: /.well-known/security.txt