trust centre

Trust Centre

Everything a security review asks for, in one place. Last reviewed: 25 August 2026.

platform security

The facts, six rows.

encryption

Edge WAF + DDoS protection · TLS 1.2+ in transit · AES-256 at rest · Ed25519 signatures on every event.

access control

Four-tier role hierarchy (viewer, member, admin, owner) · JWT with refresh-token rotation · managed identity for service-to-service auth.

data integrity

SHA-256 hash chains · append-only archive with up to 7-year retention (signed Evidence Pack handover on exit) · three-way reconciliation between ingest, query store, and durable archive.

customer-held keys

Ed25519 signing keys generated and stored exclusively in your environment; only the public key is registered with Wytness.

disaster recovery

Geo-replicated automated backups · 35-day point-in-time database recovery · documented RTO/RPO · self-healing storage with restart alerting.

audit + observability

Platform audit log of all administrative actions · anomaly detection on agent behaviour · in-app alerts for integrity gaps.

report signing

Verify our reports without an account

Distinct from your customer-held keys, Wytness holds one platform key, used only to sign the PDFs we generate. Every report carries a detached Ed25519 signature.

platform report-signing fingerprint

39032cd1b7f1f139

The last 16 hex characters of the SHA-256 digest of the platform report-signing public key. Pin against this value (or fetch the live PEM at GET /reports/platform-public-key) when you verify a signed report.

Holding an Evidence Pack? Check it against this fingerprint — in your browser, without uploading the file.

storage + residency

Where the evidence lives

wytness-hosted

Starter · Growth

Events in Wytness-managed infrastructure with logical isolation per organisation; append-only archival, backups, and reconciliation managed by us.

customer-hosted

Business +

Audit storage in your own cloud tenancy. Wytness provides SDK, signing, verification, dashboard, and alerting; the raw audit data never leaves your environment.

residency

Wytness-hosted data is processed and stored in Australia East. Business+ customers with BYOS choose their own region. Static web assets are served from the CDN's closest region and hold no customer data.

data handling

Seven commitments

  • Your data is logically isolated per organisation
  • Signing private keys never leave your environment
  • PII redaction available at the SDK level before data reaches our servers
  • Data export available at any time through the dashboard
  • 30-day data retention after account termination, followed by permanent deletion from the active store
  • Append-only archived audit events retained for their compliance retention period while you subscribe, with a signed Evidence Pack handover on exit
  • Customer-hosted storage stays in your tenancy on termination; Wytness only revokes its access

vendor attestations

What Wytness-the-vendor holds

Microsoft Partner

Active

Wytness is an active Microsoft Partner.

MIT-licensed substrate

Active

Composes on Microsoft's Agent Governance Toolkit (MIT, open source). The chain primitives under every audit entry are inspectable, not vendor-locked.

OWASP Agentic Top 10

Coverage via AGT

AGT's identity, hash-chain, and policy primitives cover the OWASP Agentic Top 10 threat surface; Wytness inherits that coverage in the wrapper SDK.

Penetration test

Scheduled Q3 2026

First annual third-party pen test: ingest, dashboard, per-organisation isolation, PII middleware. Summary on request under NDA after the first report lands.

We set no cookies. Sign-in and preferences use essential first-party browser storage only — no tracking, advertising, or third-party analytics. Privacy Policy