Before you can mint API keys or create sessions, please review and accept the following:
Active sessions
— / —
running now · concurrent cap is the only meter
Profiles
—
saved identities
Session hours
—
this billing cycle
Plan
—
Your data is protected
Saved profile state and recoverable credentials are encrypted at rest with context-bound wrapping under platform-held keys.
Profile encryption
AES-256-GCM at rest
Profile state is stored as ciphertext; when it is used, the platform unwraps its bound key for that authorized session.
Envelope binding
Context-bound encryption
Authenticated encryption binds wrapped values to the owning account and, for record-scoped stores, the exact record and value slot.
Credential audit
Recorded management events
Review credential-management events that were recorded in your audit log. Routine runtime use is not logged as a credential-read event.
Full model at driftstack.dev/trust · export and deletion are request-based today; start from Privacy & security.