Security review

Convert trust controls into customer-ready evidence.

Review pilot-critical controls and the next hardening step needed before handling production workloads.

Customer API-key access

watch

Owner: Security

Evidence: /customers/keys and /api/customer-api-keys/list

Add request signing, hard quotas, and per-customer rate limits.

Node telemetry trust

ready

Owner: Infrastructure

Evidence: /nodes/keys, SHA-256 node-key hashing, telemetry validation

Add signed agent releases and telemetry replay protection.

Data residency routing

watch

Owner: Compliance

Evidence: /routing, /regions, /compliance/evidence

Export route decision evidence bundle per customer and region.

Operational auditability

ready

Owner: Platform

Evidence: /admin/audit and audit_events schema

Add immutable append-only mode and export signatures.
Security Review | UmamiEdge