Published standard · Evidence v1
Security
These controls describe the product implementation. CIP does not claim SOC 2 or ISO certification.
Access control
Customer data is scoped by organization and project. Private evidence requires a session; public shares use unguessable, revocable, time-limited tokens.
Keys and integrity
Provider credentials are encrypted. Public reports use Ed25519 signatures and SHA-256 manifest hashes.
Outbound verification
Source checks restrict protocols, redirects, size, and time while blocking private, loopback, link-local, and cloud metadata addresses.