Customer API-key access
watchOwner: Security
Evidence: /customers/keys and /api/customer-api-keys/list
Add request signing, hard quotas, and per-customer rate limits.
Review pilot-critical controls and the next hardening step needed before handling production workloads.
Owner: Security
Evidence: /customers/keys and /api/customer-api-keys/list
Owner: Infrastructure
Evidence: /nodes/keys, SHA-256 node-key hashing, telemetry validation
Owner: Compliance
Evidence: /routing, /regions, /compliance/evidence
Owner: Platform
Evidence: /admin/audit and audit_events schema