Technical disclosure · Trust overview

Inspect the technical boundary before you deploy.

These pages describe controls and operating limits that are visible in Korve's current product contract and tests. They are technical disclosures. They are not legal terms, a privacy notice, a certification, or an availability promise.

Identity and authorization

  • Organization roles are ordered owner, admin, and member. Each operation declares its minimum role, and the control plane applies that rule to dashboard sessions and organization API keys.
  • Organization API keys are scoped to one organization. Only a SHA-256 digest is stored after the full key is shown once.
  • A request for another organization does not reveal whether the addressed resource exists. Public errors use stable, redacted codes for automation.

Secrets and sensitive operations

  • Project environment-variable values use authenticated AES-256-GCM encryption at rest. Manifest exports replace their values with a preserve-live-value marker.
  • Customer payment connection secrets use a separate rotatable AES-GCM keyring. Queue message bodies are encrypted before the shared delivery path receives an opaque pointer.
  • Sensitive agent mutations can pause for a human decision. The service checks current authorization again before it applies an approved action.

Audit and evidence

  • Every organization write operation is recorded with actor, outcome, status, and bounded request context. Failed write attempts are included; reads are not.
  • Organization audit entries are retained for 90 days. Secrets, environment-variable values, passwords, tokens, and email links do not belong in audit context.
  • Public benchmark pages label lab evidence as lab evidence. They do not turn a local result into a production service objective.

What is not claimed

This disclosure does not claim a compliance certification, a complete encryption guarantee for every storage layer, a penetration-test result, a bug bounty, a fixed security response time, or continuous human monitoring. Korve does not publish a security mailbox until a monitored address and response process exist.