Architecture
One architectural decision does most of the work: the control plane is ours and the data plane is yours. Everything else follows from refusing to move evidence across that boundary.
The layers
Instruments five choke points rather than two hundred frameworks. That is how the install stays under an hour.
Absorbs bursts on a durable queue so capture never blocks and nothing is lost under load.
Canonicalises, hashes and hybrid-signs every change. The trust-critical core, and the reason it is Rust.
Append-only, signed tree heads, RFC 6962 lineage. Reused, never hand-rolled — a bespoke Merkle log is how you ship a subtle break.
Right tool per job: lineage graph, evidence blobs, cost analytics, estate-wide search.
Decides what each change needs, then does it. This is where “nobody writes the documentation” actually happens.
Search, lineage, reports, and a one-click verifiable audit export.
Fleet health, updates, licensing and billing. Carries no customer evidence or PII — by construction, not by policy.
Trust
The useful question about any evidence system is not what it proves but who it still requires you to trust. Here is the honest answer, including the parts that are uncomfortable.
Failure model
An infrastructure product is bought or rejected on this table more than on any feature.
Deployment
The same package runs all three. We never fork the product per customer — the thing that quietly kills enterprise infrastructure startups.
SMB and mid-market who want to start today
Managed control and data plane, with per-tenant cryptographic isolation.
Most enterprises
Data plane runs in the customer's own cloud; we manage the control plane. Their data never leaves.
Defence, government, top-tier finance
Full stack via Helm, with zero outbound calls.
The evidence path