Published standard · Evidence v1

Security

These controls describe the product implementation. CIP does not claim SOC 2 or ISO certification.

01

Access control

Customer data is scoped by organization and project. Private evidence requires a session; public shares use unguessable, revocable, time-limited tokens.

02

Keys and integrity

Provider credentials are encrypted. Public reports use Ed25519 signatures and SHA-256 manifest hashes.

03

Outbound verification

Source checks restrict protocols, redirects, size, and time while blocking private, loopback, link-local, and cloud metadata addresses.