BengarTrust infrastructure

Product

Bengar Custody AVAILABLE

Self-hosted software custody. Not an HSM, and it says so.

What it is

Why it exists

How it works

Who uses it

Security boundary

  • SOFTWARE CUSTODY, not an HSM. During one signing operation the key is in process memory.
  • Custody down is not authorization down; it is reached only at the signing boundary.
  • No caller can hand it bytes, a digest or a raw sign document — there is no field for one.

Example flow

A stolen volume

  1. An attacker copies the database volume.
  2. Every private key in it is ciphertext.
  3. The KEK is a mounted secret and is not in that volume.
  4. Without it the copy yields nothing usable.

Current status

CapabilityStatusWhere
Provision or retire a Custody approval keyAVAILABLE/projects/:id/security/approval-signing

Documentation