Security, privacy and audit requirements · C0898
How often would encryption keys be rotated?
Designed, not yet built
Short answer
Keys must be rotated on schedule and on compromise; rotation intervals are (still an open decision) with design proposals. That is REQ-4604, a top-priority requirement for all three tiers. This is on the design side of the line. Nothing in v0.2.0 does it. Test in the specification: rotation job re-wraps DEKs without downtime. Parts of it are explicitly marked as open in the specification.
This is designed, not built.
- Specification item
- REQ-4604
- Specification priority
- P0 (of P0 to P3)
- Tiers
- Small, Medium, Large
Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.
Related answers
- How would key ceremonies be run and recorded? Designed
- Which password hashing method does the specification call for? Designed
- Is the cryptography designed to be swapped out later, for example for post-quantum methods? Designed
- Where would root and master keys be kept? Designed
See it in context: Key management · Search the help center · Ask a question