← Back to Verigate

Security

Last updated: June 2026

Cryptographic Design

Authorization Path

Zero LLM in the trust path. The authorization gateway is fully deterministic — policy evaluation uses allowlist, resource scope, and rate limit rules. No AI model can influence an authorization decision. AI (Gemini) is used only for compliance analysis, support, and recommendations — never for allow/deny decisions.

Infrastructure

Authentication

Verification

Receipt chains can be independently verified by anyone with the public key (GET /v1/public-key or GET /v1/engine/public-key). On-chain anchors can be verified on BaseScan. No trust in Verigate is required for verification.

Responsible Disclosure

Report security vulnerabilities to security@verigate.cloud. We will acknowledge within 24 hours.