Security & trusted evidence
Cridenty
Our approach: trust through evidence
Cridenty is designed as a trust infrastructure for critical operations. Our goal is not to monitor, intercept or analyze communications, but to produce verifiable evidence, independent from the channel, usable for audits and dispute resolution.
Trust is not declared — it is proven.
Security by design
Security is not a feature added afterwards. It is built into the platform from the start, at every level:
- strict separation of roles and workspaces,
- data minimization,
- strong access controls,
- systematic traceability of critical actions.
Cridenty applies Security by Design and Privacy by Design principles.
Strong authentication, at the right moment
Cridenty relies on modern, phishing-resistant authentication mechanisms:
- FIDO / WebAuthn (hardware keys, passwordless authentication),
- adaptive step-up for sensitive actions,
- policies configurable per organization (tenant).
Strong authentication is triggered only when needed, to balance security and user experience.
Cryptographic evidence independent from the channel
Cridenty does not transport messages and does not depend on the delivery channel.
Whether a message is sent via:
- SMS,
- email,
- a business application,
- a voice channel or a document,
Cridenty makes it possible to:
- generate a timestamped cryptographic proof,
- associate that proof to a short, human-friendly identifier,
- later verify the exact integrity of the content (true copy).
The channel may be compromised — the proof remains verifiable.
Technical processing without storing content
Content submitted to Cridenty is:
- processed in a strictly technical and transient way,
- used only to compute a signature or hash,
- never stored in clear text.
Cridenty:
- does not analyze content,
- does not exploit it,
- does not sell it,
- does not perform profiling for commercial, advertising or HR purposes.
Scores, correlations and classifications produced by Cridenty Guard are technical security signals intended to assess whether an action complies with a policy, not to assess a person’s performance, behavior or productivity.
The platform stores cryptographic proofs only — not the messages themselves.
Traceability and auditability
Each critical action is:
- timestamped,
- logged,
- associated with context (tenant, agent, session, operation).
This traceability enables:
- internal audits,
- regulatory compliance,
- dispute resolution,
- good-faith demonstration in case of a challenge.
Cridenty Guard / Agent Guard
Some Cridenty features, including Cridenty Guard or Agent Guard, may collect technical runtime signals to verify that an AI tool, software agent, script or development environment remains within the scope authorized by the organization.
Depending on the configuration chosen by the customer, these signals may include:
- the action type,
- the process involved,
- pseudonymized technical identifiers,
- normalized path information,
- target fingerprints,
- policy decisions,
- risk scores,
- timestamps.
These features are not intended to assess individual users or perform HR monitoring. They are designed for security, AI agent governance, detection of out-of-scope actions and the construction of control policies.
A dedicated notice describes the processing of Cridenty Guard technical security signals.
Verifiable and exportable proofs
Proofs generated by Cridenty can be:
- verified via a public API/page,
- associated with short identifiers (error-proof UX),
- exported as signed artifacts (e.g., signed JSON, JWS).
They are designed to be:
- understandable,
- verifiable,
- usable by third parties (audit, compliance, legal).
Enhanced timestamping (advanced option)
For advanced compliance needs or long-term retention, Cridenty can optionally provide:
- periodic anchoring of proofs (chaining, Merkle),
- publication of immutable anchors,
- retention on storage with configured policies.
This option further strengthens the evidentiary value of proofs over time.
Operational security
Cridenty implements technical and organizational measures aligned with industry best practices, including:
- strict access controls,
- secrets and keys protection,
- multi-tenant isolation,
- monitoring and logging of sensitive events.
Cridenty is bound by an obligation of means, with a focus on reliability and resilience.
A trust platform, not a communications intermediary
Cridenty is not:
- a telecom operator,
- a messaging service,
- a surveillance tool.
Cridenty is a trusted third party whose role is to produce and verify evidence, without interfering with communications.