Skip to content
SECURITY / OPERATIONS

Trust is
operational.

LedgerLayer cannot sell credible evidence if the operational layer silently rewrites history, leaks tenant data, runs arbitrary customer code inside the public API, loses signing history, or has never restored its backups.

DESIGN PRINCIPLES

Boring infrastructure.
Durable evidence.

The initial production model deliberately avoids gratuitous microservices. The difficult work is isolation, versioning, signing, recovery, and auditability — not architectural theater.

01

Immutable artifacts

Engine IDs bind to artifact digests. Historical competitions keep their original semantics forever rather than following “latest.”

02

Sandbox execution

Untrusted adapters run with CPU and memory limits, network disabled where possible, read-only filesystems, deterministic runtime settings, and explicit deadlines.

03

Key separation

API authentication keys, receipt signing keys, webhook keys, internal credentials, and optional anchor accounts are independent responsibilities.

04

Historical verification

Signing key rotation retains the public material and policy needed for old receipts to remain verifiable.

05

Tenant isolation

Games, competitions, credentials, evidence, usage, and operator actions are tenant scoped unless a resource is explicitly public.

06

Restore, don't assume

Backups are not considered tested until database and evidence restoration has actually been executed under a documented recovery drill.

07

Abuse boundaries

Transcript size, evidence size, request rate, socket count, agent actions, and expensive verification work receive independent limits before costly processing.

08

Independent qualification

Production readiness ultimately requires external security assessment rather than a platform declaring itself secure because its own test suite is green.

SECURITY QUALIFICATION

Evidence is a promise
that outlives a deploy.

Production launch requires tenant-isolation testing, fuzzing, rate-limit tests, replay-bomb tests, WebSocket abuse tests, sandbox review, secret scanning, recovery drills, and independent assessment.