trust centre
Trust Centre
Everything a security review asks for, in one place. Last reviewed: 25 August 2026.
platform security
The facts, six rows.
encryption
Edge WAF + DDoS protection · TLS 1.2+ in transit · AES-256 at rest · Ed25519 signatures on every event.
access control
Four-tier role hierarchy (viewer, member, admin, owner) · JWT with refresh-token rotation · managed identity for service-to-service auth.
data integrity
SHA-256 hash chains · append-only archive with up to 7-year retention (signed Evidence Pack handover on exit) · three-way reconciliation between ingest, query store, and durable archive.
customer-held keys
Ed25519 signing keys generated and stored exclusively in your environment; only the public key is registered with Wytness.
disaster recovery
Geo-replicated automated backups · 35-day point-in-time database recovery · documented RTO/RPO · self-healing storage with restart alerting.
audit + observability
Platform audit log of all administrative actions · anomaly detection on agent behaviour · in-app alerts for integrity gaps.
report signing
Verify our reports without an account
Distinct from your customer-held keys, Wytness holds one platform key, used only to sign the PDFs we generate. Every report carries a detached Ed25519 signature.
platform report-signing fingerprint
39032cd1b7f1f139
The last 16 hex characters of the SHA-256 digest of the platform report-signing public key. Pin against this value (or fetch the live PEM at GET /reports/platform-public-key) when you verify a signed report.
Holding an Evidence Pack? Check it against this fingerprint — in your browser, without uploading the file.
storage + residency
Where the evidence lives
wytness-hosted
Starter · Growth
Events in Wytness-managed infrastructure with logical isolation per organisation; append-only archival, backups, and reconciliation managed by us.
customer-hosted
Business +
Audit storage in your own cloud tenancy. Wytness provides SDK, signing, verification, dashboard, and alerting; the raw audit data never leaves your environment.
residency
Wytness-hosted data is processed and stored in Australia East. Business+ customers with BYOS choose their own region. Static web assets are served from the CDN's closest region and hold no customer data.
data handling
Seven commitments
- ✓Your data is logically isolated per organisation
- ✓Signing private keys never leave your environment
- ✓PII redaction available at the SDK level before data reaches our servers
- ✓Data export available at any time through the dashboard
- ✓30-day data retention after account termination, followed by permanent deletion from the active store
- ✓Append-only archived audit events retained for their compliance retention period while you subscribe, with a signed Evidence Pack handover on exit
- ✓Customer-hosted storage stays in your tenancy on termination; Wytness only revokes its access
vendor attestations
What Wytness-the-vendor holds
Microsoft Partner
Active
Wytness is an active Microsoft Partner.
MIT-licensed substrate
Active
Composes on Microsoft's Agent Governance Toolkit (MIT, open source). The chain primitives under every audit entry are inspectable, not vendor-locked.
OWASP Agentic Top 10
Coverage via AGT
AGT's identity, hash-chain, and policy primitives cover the OWASP Agentic Top 10 threat surface; Wytness inherits that coverage in the wrapper SDK.
Penetration test
Scheduled Q3 2026
First annual third-party pen test: ingest, dashboard, per-organisation isolation, PII middleware. Summary on request under NDA after the first report lands.
documents
The review pack
Security questionnaires, compliance enquiries, DPA requests, or additional documentation: support@wytness.ai.