Skip to content
Vertex Lake
Menu

Trust · from the assurance pack

Shared responsibility

Published from docs/assurance/shared-responsibility.md as it ships with the software: the same text an auditor receives. A reference to another document of the pack or to a runbook is named, not linked; they ship beside it.

Who guarantees what. "Product" = enforced by shipped code (usually at the database, binding every role). "Operator" = the deploying organization. "Vendor-operated services" are the customer portal and the release registry (ADR-0025, ADR-0027): the account, the licences, the signed releases; never an instance's data.

Area Product guarantees Operator responsibilities
Access control RLS need-to-know, barriers, roles, emergency access semantics; fail-closed defaults Assigning grants/barriers that reflect real conflicts; reviewing the per-workspace access report
Identity Password hashing, MFA machinery, SSO/SCIM correctness, session hygiene Requiring MFA/SSO; IdP configuration; joiner-mover-leaver process
Audit Attribution, append-only hash chain, anchors, verification tools Running verification on a schedule; keeping an off-host export; acting on findings
Records No-hard-delete guarantee, holds that freeze, certificates, review queue Setting retention schedules; deciding dispositions; scoping holds
The appliance One-command install, one address, TLS from one of four sources (a private authority, Tailscale, your own certificate, Let's Encrypt through DNS-01), units that start at boot, a console command, a recovery kit written at install Keeping the recovery kit off the machine; installing the CA on clients; the machine's own patching and physical security
Updates Channel tags, images signed with the vault-held release key on the vendor's registry (ADR-0025), a policy-driven update step with a pre-update dump and rollback, the state shown in the product Choosing the channel and the window; keeping the licence current for updates; restoring the pre-update dump when going back is wanted
The vendor's services The customer portal, the registry and the mail it sends (ADR-0025, ADR-0027 to ADR-0029, ADR-0031): passwordless sign-in with an optional second factor, an audit chain of the portal's own, licences issued through an HSM-held key, credentials revocable one by one, Stripe holding every card, account data in the vendor's Azure resource group with its own backups (seven days, not geo-redundant), Stripe and Microsoft Azure as the only sub-processors; the vendor's administration on its own host, reachable from the vendor's networks alone and absent from the public portal's routes, document and bundle Keeping the account's people current (removing leavers, one owner at least); keeping the install kit and its credential off the appliance's exports; turning the second factor on; telling the vendor of a leaked credential
Licences Offline verification with the vendor's key (held in an HSM-backed vault, ADR-0026); a commercial licence that verifies gates additions and updates, never operation; an instance with no licence that verifies (never licensed, an ended evaluation, a file the build no longer trusts) is locked and its workers claim nothing until one is installed; the install kit and the daily refresh (ADR-0027); every install on the audit trail Installing the licence the vendor issued; renewing maintenance for updates and support; naming the premium modules bought
Transport crypto TLS implementation, HSTS, FIPS build option Certificates and their rotation; choosing the FIPS build when required
At-rest crypto Sealing of stored credentials Volume/storage encryption; custody of the instance key
Availability & DR The product's own scheduled backups to destinations the customer names (ADR-0022): each a snapshot anyone can open with stock tools, with a signed manifest and a verifier (--verify-restore --all, drill-restore.sh); restore documentation Naming destinations and keeping a copy off-host; keeping the recovery kit off the machine and adding each destination's repository password and credentials to it by hand (they are typed after the install, sealed and never shown again — without them no backup opens); restoring and proving a copy on a schedule of their own; capacity
Vulnerability mgmt Coordinated disclosure, CRA reporting, SBOMs, signed releases, declared support period Applying updates promptly; subscribing to advisories
Modules and regulated features One registry enforced by the API, the worker and the UI; deployment locks above the administrator's switch; switching off never deletes records; every switch, refusal, acceptance and lock change on the audit trail; regulated features off by default, and on only with a named person's acceptance of a versioned notice Deciding which modules your deployment may offer and locking the rest; stating where the instance operates; the lawfulness of any regulated feature you switch on (your legal basis, impact assessment, consent and retention decisions); any model or hash set you register
Provenance and integrity (ADR-0017) Checksums computed on arrival and read back on a schedule; every arrival recorded; hash-set matching by the checksums every file carries; the export that carries the record and refuses bytes that changed Naming custodians and acquisitions; the hash sets you import and their terms (NSRL's redistribution terms, Project VIC and CAID entitlement); the fixity window and byte budget; acting on a failed read-back
Court bundles (ADR-0019) Pagination from 1, bookmarks, a linked index, verification against the judiciary's 2021 guidance on every build; pages frozen once served, late additions paginated on with a supplement The court's own directions (size limit, filing route), what goes in, when it is served
Legal discovery (ADR-0020) Load files read as they are; every row a document; append-only coding that no save overwrites unseen; exact review search; redaction that fails closed; numbered outputs read back before they are offered and frozen once sent; assisted review that never codes The jurisdiction profile and its vocabulary; review decisions, privilege calls and proportionality; the interpretation of a recall estimate; the retention of matters and their outputs
Legal forensics (ADR-0018) Evidence mode's gate at every byte site and dual control; the hash-chained custody record and its offline verifier; timestamps verified against the chain you name; PDF/A-3u reports and records; validation packs run and recorded; quarantine; sealed, unindexed biometric templates with destruction certificates; indicators that name their audit range; at-least-once SIEM forwarding The time-stamping authority and its chain; the SIEM receiver and what it keeps; the lawful basis, impact assessment, consent and retention date for every biometric subject; the labelled sets a calibration is fitted on and their fitness for the case; the legal procedure on a restricted match and your entitlement to the sets; any perceptual matcher, detector or embedder you register; the integrity and custody of forensic images under the read-only roots; whether the worker may resolve names for email authentication; method validation and accreditation for court (the packs are evidence that a method behaves as documented — the FSR Code, ISO/IEC 17025 and the court's acceptance are yours to meet)
Physical & platform — Servers, OS patching, network segmentation, physical access
Legal & regulatory Evidence and controls that support compliance The compliance itself: your retention schedule, your ethics screening decisions, your regulator relationships

Certification boundary, stated plainly: certificates like SOC 2 or ISO 27001 attest an operation. For self-hosted VX Drive, the operation is yours, so those certificates are yours to earn — this pack exists to make that cheap. The services the VX Drive vendor operates (the portal and the registry) hold your account, your licences and the signed releases; any attestation of those services — per the certification roadmap — covers them only, never your instance.