Operate
Security
Fidacy sits on the money path, so its security model is conservative by construction. The guiding rule: the system fails safe, proves everything, and isolates every tenant, at the database, not just the app.
Fail-safe by construction
A consequential integration must fail closed at its own execution boundary. Fidacy returns review where an assessment can be completed conservatively; dependency failures such as unavailable storage or signing keys return errors. Neither outcome is permission to execute. A connected executor must reject a missing, expired or replayed action grant.
Cryptography
- ·Risk Payloads are signed with EdDSA (Ed25519) and published as compact JWS. Anyone verifies them against the public JWKS at
/.well-known/jwks.jsonbykid. - ·The private signing key is held only in the runtime secret store and never touches the database. The verify URL travels in the payload so verification needs no Fidacy round-trip.
- ·Agent keys are identified by their RFC 7638 thumbprint; an embedded, unverified key is self-asserted and cannot earn trust, preventing key-confusion and forged-card attacks.
Tenant isolation
- ·Tenant-owned records are organization-tagged and protected by row-level security, including
FORCEwhere the table must remain protected even from owners. Platform-wide operational tables use separate, purpose-limited access paths. - ·The runtime connects as a least-privilege role, not the database owner. Cross-org discovery (for background workers) goes through narrowly-scoped functions that expose only ids, never data.
Keys & secrets
- ·API keys are stored only as SHA-256 hashes; the raw value is shown once. Revocation is instant and takes effect on the next request.
- ·Use least-privilege scopes per workload. Rotate keys on a schedule and immediately on any suspected exposure.
- ·Secrets live only in your environment/secret manager, never in source control, logs, or screenshots.
Non-repudiable audit
Decisions and artifacts are appended to a hash-linked audit trail and can be sealed in Merkle checkpoints. A signature and anchor make later alteration detectable; they do not prove that Fidacy observed every action in an external system. Use Control Coverage to disclose the live boundary, retention and known evidence gaps.
Data handling
- ·The optional reasoning layer receives only non-sensitive signals (scores, flags, codes), never raw PII or payment credentials.
- ·Assessments store the structured signals needed to reproduce the verdict, not the user's payment instrument secrets.
security@fidacy.com with details and a proof-of-concept. We respond quickly and credit reporters.