Security

You should not have to trust us.

Notaree custodies other companies’ evidence. That makes security the product rather than a feature of it. This page states our posture, including the parts that are not finished.

The property that matters most

Every bundle verifies without us.

An evidence bundle is checked by an open-source verifier that makes no network calls and trusts no server — in TypeScript, or in pure Python with zero dependencies, so an auditor can run it against a stock interpreter. Two independent implementations reproduce a committed conformance corpus byte for byte.

If our infrastructure were entirely compromised, a verifier would still detect any alteration of existing evidence.

What we defend, and how

Implemented today.

Tamper-evident by construction

Each record commits to the hash of the one before it. Batches are committed to an RFC 6962 Merkle root and signed in a hardware key store, where the private key cannot be exported.

Tenant isolation in the database

Postgres row-level security is FORCE-enabled per table and is the enforcement boundary — not application filtering. A cross-tenant test runs in CI against a real Postgres on every push.

Redaction before persistence

PII is removed in the ingest path before anything is written, fails closed, and records its ruleset version. Hash-only mode chains the payload hash without storing the payload at all.

No customer provider keys

We never store your LLM provider API keys. Holding them would make us a far more attractive target for no product benefit.

Append-only

The database forbids deletion of chain records. Retention expiry is an event, not a silent removal. Signed roots are mirrored to immutable object storage.

Agent behaviour, watched twice

Actions are scored against a policy you declare — once in-process where a run can still be halted, and again after the record leaves your process, where your agent cannot switch it off.

What we do not defend against

Stated plainly, because you would find out anyway.

  • We cannot attest to what was never sent. We record faithfully what reaches us. An agent that routes around its own instrumentation is invisible to any SDK-level recorder, ours included — this is a documented technique, not a hypothetical.
  • We are not a sandbox, a WAF, or an EDR. Detection narrows the window and raises the cost of an incident. It does not prevent one, and we will not claim a percentage.
  • A compromise of our signing key would let an attacker forge new attestations going forward — but not silently alter existing anchored evidence. Hardware custody and signed key rotation bound this.
  • We hold no SOC 2 today. It is on the roadmap and we will not claim it until it is achieved.
  • No external cryptographic review yet. Correctness currently rests on 100% branch coverage of the integrity core, property-based tests, a committed conformance corpus, and two independent implementations that agree. A third-party review is funded from early revenue.
Reporting a vulnerability

Tell us, and we will credit you.

Email eckoeyo@gmail.com with details and a proof of concept if you have one. We aim to acknowledge within two business days and ask for a reasonable window to remediate before public disclosure. We do not run a paid bounty yet; we will credit reporters who want to be named.

Machine-readable contact: /.well-known/security.txt

This page describes our engineering posture. It is not a compliance certification and not legal advice.