Platform security controls
All data in transit is encrypted using TLS 1.2 or higher. All data at rest is encrypted. The provenance ledger is append-only and cryptographically signed; each credential carries an integrity hash that can be verified against the public registry. Access to operator functions requires multi-factor authentication (MFA); MFA is mandatory for all accounts with the ability to submit, review, or determine certification. Authentication events and all operator actions are recorded in an immutable audit log.
Key management (CUSTOS)
Credential signing keys are managed through CUSTOS, Veritan's key management subsystem. Signing keys are isolated from application code, rotated on a defined schedule, and subject to dual-control access policies for Tier 4 credential issuance. Key compromise is treated as an incident requiring immediate revocation of affected credentials and notification to affected credential holders. The current trust firewall digest is published in the platform's status feed.
Operator access controls
Operator-level access to the certification workflow is governed by role-based access control. The principle of least privilege is applied: reviewers may access only the records assigned to their queue; administrators may manage accounts but not issue credentials directly; and authority flags required for production issuance are separately governed and fail-closed by default. All access is logged and audited.
Responsible disclosure
If you believe you have discovered a security vulnerability in the PROVENANCE VERIFIED™ platform, please report it to security@provenanceverified.org. Include a description of the vulnerability, steps to reproduce it, and any supporting evidence. Please do not publicly disclose the vulnerability until we have had a reasonable opportunity to investigate and remediate. We aim to acknowledge receipt within 2 business days and to provide a substantive response within 10 business days.
Bug bounty
We do not currently operate a public bug bounty program. We appreciate responsible disclosure and will acknowledge researchers who report valid vulnerabilities in our release notes, where the researcher requests attribution and has complied with our disclosure policy. We reserve the right to establish a formal bug bounty program in the future.
Incident notification
In the event of a security incident that affects the confidentiality, integrity, or availability of customer data, we will notify affected customers as required by applicable law and as promptly as operationally feasible. Notifications will include a description of the incident, the categories of data involved, steps we have taken, and steps customers can take to protect themselves. Incident status is communicated through status@provenanceverified.org and the platform status page.