# ETP Foundry — Security overview **Version 0.1 · 28 September 2026** A one-page summary of how the service is built and protected, including what is not yet in place. A fuller vendor due-diligence pack is available on request under NDA. ## Hosting - Google Cloud, region `us-central1`: the desk API, the hosted MCP and the vault deployer run on Cloud Run; our Canton DevNet validator runs on one Compute Engine VM. The website is on Firebase Hosting. - The validator VM has no public SSH port. Operator access is through Cloud IAP only, with OS Login. Its ledger port is reachable only from the desk's own subnet. - Everything is DevNet or public testnet. Nothing runs on any mainnet. ## Authentication and access - **People** sign in with Google through Firebase Authentication, the only sign-in method. The e-mail must be verified and on the desk's roster; anyone else is refused. - **Programs** use `ck_` API keys: 256-bit random, shown once, stored only as a SHA-256 hash, never logged. The hosted MCP (etpfoundry.com/mcp) uses the caller's own key and role. - Six roles; route permissions are declared in one place and tested. The public, unauthenticated API is read-only. - The in-console assistant acts with the signed-in user's own credentials and cannot write anything without the user's approval (see the AI-use disclosure). ## Secrets and keys - Google Secret Manager is the only store for secrets. Services receive secret references, not values. - Published reports are signed with ES256 (P-256). Public keys are at /.well-known/etpfoundry-signing-keys.json, and any report can be checked at etpfoundry.com/verify. - Committee seats that sign at trust level L2 hold their own keys. Those keys never leave the seat. ## Encryption - HTTPS for the site, API and MCP, with standard security headers on every path. - Data at rest uses Google's default encryption. No customer-managed keys are configured. - The link from the desk to our Canton participant is plaintext gRPC inside a private network, authenticated with a shared secret. Moving to TLS and OIDC is required before TestNet or MainNet. ## Monitoring - The admin console shows chain-watcher and desk alerts (since 27 September 2026). - There is no uptime check, paging tool or on-call rota yet. ## Assurance - **No independent security audit** of the Daml packages, the backend or the EVM vault contracts has been performed. No SOC 2 or ISAE 3402 report exists. - Internal reviews and their open findings are written down and available under NDA. ## Reporting a vulnerability E-mail **security@etpfoundry.com** (also listed at etpfoundry.com/security.txt). We acknowledge within 2 business days. Please give us 90 days to fix an issue before disclosing it publicly. We do not take legal action against good-faith research that avoids harm to data and service. See also: incident response (incident-response-v0.1.md) and business continuity (business-continuity-v0.1.md). Lucilla, Inc., federal corporation no. 16699448, Toronto, trading as ETP Foundry.