IndeProof

Security & Data

The security posture of a company whose product is honesty.

These are practices we actually operate, stated at the scope we actually operate them. No certifications are claimed, because none have been earned yet.

Separated identities, least privilege

The producing system and the verifying system never share credentials. The verifier holds its own identity with the minimum access that verification requires — read-only wherever the proof source allows it. In the internal pilot, the verifier's entire scope is read access to contact records; the producer's write scopes are never granted to it.

Data minimization

IndeProof verifies presence, identity, and timing of contracted outcomes. It does not ingest datasets wholesale. Evidence artifacts preserve payload digests, keyed integrity tags, timestamps, and classification decisions — not credential material, and not data beyond what the frozen contract requires observing.

Credential handling

  • Secrets live only in managed secret storage — never in code, shells, screenshots, chat, or evidence artifacts.
  • Never send credentials, API keys, tokens, or confidential evidence through this website or by introductory email. Qualification never requires them.
  • If a pilot requires access, it is scoped to least privilege and exchanged over an agreed private channel — after qualification, never before.

Evidence-access boundaries

Original decisions are never overwritten; contradictions create linked superseding artifacts. Every artifact carries a payload digest and a keyed integrity tag, so alteration — a single digest mismatch — is detectable on verification.

This website

This site sets no cookies, runs no analytics, loads no third-party scripts, and has no forms — it collects nothing. Contact is by email only; qualification email is read by the founder and used solely for the qualification conversation. Details: Privacy.

Reporting a security concern

Email alex@indeproof.com with the subject "Security concern". Do not include exploit payloads, credentials, or personal data in the first message.

Current scope, stated honestly

  • All development and testing to date has occurred in an isolated developer test environment. No customer or production data has been used or accessible. The planned internal pilot has not yet been executed.
  • No security certifications, audits, or compliance attestations are claimed. When they exist, they will be named precisely; until then, nothing is implied.
  • Retention commitments beyond the pilot's evidence-preservation rules are not yet published, because unsupported commitments would violate the claim discipline this company exists to enforce.