Security, privacy and audit requirements
Key management
Hierarchy, HSM, rotation, ceremonies.
How to read status labels: In the pilot (v0.2.0, synthetic data) Simulated in the pilot Coming (Wave 2, rolling out) Designed, not yet built Open decision Not offered / no claim made Planned partner integration
C0895How are encryption keys arranged, from the root key down to the data key?
The key management part of the specification (REQ-4601) says keys must follow the hierarchy Root -> Master KEK -> Sphere KEK -> Compartment KEK -> DEK with envelope encryption. No. The specification describes it, but the pilot does not include it. Acceptance check: unwrapping chain test; no DEK stored in plaintext.
C0896Where would root and master keys be kept?
How would it be tested? The specification says key export from HSM fails. That is the check for REQ-4602: root and master keys must be in an HSM or equivalent secure element; large tier requires FIPS 140-validated HSM (to be verified); small tier may use a TPM-sealed or smartcard-based custody. Not yet. It is designed in the specification and not built in the pilot.
C0897How would key ceremonies be run and recorded?
Designed, not built: there is no code for this in the pilot. For reference, REQ-4603 (a top-priority requirement, all three tiers) says key ceremonies must be scripted, witnessed, logged, with split custody (Shamir) and documented recovery. Check: ceremony checklist artifact stored.
C0898How often would encryption keys be rotated?
Keys must be rotated on schedule and on compromise; rotation intervals are (still an open decision) with design proposals. That is REQ-4604, a top-priority requirement for all three tiers. This is on the design side of the line. Nothing in v0.2.0 does it. Test in the specification: rotation job re-wraps DEKs without downtime. Parts of it are explicitly marked as open in the specification.
C0899Which password hashing method does the specification call for?
No. The specification describes it, but the pilot does not include it. REQ-4605 says password hashing must use Argon2id with at least 64 MiB memory and t>=3, or an equivalent tuned for the server. Its acceptance check: parameter check on deploy.
C0900Is the cryptography designed to be swapped out later, for example for post-quantum methods?
REQ-4606 is a high-priority requirement for the medium and large tiers: cryptographic modules must support agility, including hybrid X25519+ML-KEM-768 for key establishment; ML-DSA signatures are optional and (still an open decision). Not yet. It is designed in the specification and not built in the pilot. To verify it, the specification says suite negotiation test. Parts of it are explicitly marked as open in the specification.