CipherStashDocs
Architecture & security

Architecture & security

Trust model, cryptographic design, availability, audit, and compliance, written to be read end to end during a vendor security review.

This section is written to be self-contained. A security team should be able to assess CipherStash from these pages without piecing the story together from reference material elsewhere.

Start with Cryptography. It is the canonical account of the cryptographic design: the key hierarchy, what ZeroKMS learns and does not learn, and what is cached. Every other page that touches key management links to it rather than restating it.

In this section

  • Cryptography covers the primitives, the key hierarchy, the trust model, and the data flow.
  • Compliance maps CipherStash onto specific frameworks.

On this page