Trust

What actually protects a Witness record.

Identity, access, audit and recovery, stated as what runs in production today - not what is designed, configured, or aspired to.

Deployed today

What is actually running

Identity through Keycloak, not a homegrown login

Authentication is delegated to Keycloak over OIDC. Witness never stores a password.

Deny-by-default access control

Every request resolves the caller's role and scope, then checks it against an explicit policy. The absence of an explicit allow is a denial, not a fallback to permissive behaviour.

Server-managed sessions

The browser session cookie is HttpOnly, marked Secure in deployed environments, and scoped to a single origin. It carries no data a script running on the page could read.

Tamper-evident audit trail

Every recorded action is chained to a hash of the one before it. Altering or deleting a past event breaks every hash after it, so tampering is detectable by recomputation - not by trusting that nobody with database access would do it.

Backups with a proven restore, not just a schedule

A full, isolated restore drill has recovered real rows from a production backup on disposable infrastructure, destroyed afterward. A backup that has never been restored is a hope, not a control - this one has been exercised.

Not yet

What is configured, planned, or not started

Database row-level security

Tenant isolation is enforced in the application/repository layer today. A second, independent database-level layer is planned and not yet built.

Enforced API rate limiting

Rate-limit configuration exists in the codebase. It is not yet wired into an enforced production control.

Third-party security certification

No SOC 2, ISO 27001, or equivalent audit has been completed. This page will not claim one until it has.

Ask your own security team to review what we run.