/privacy — ZERO-PII & HARDWARE HSM POLICY
Cryptographic data isolation protocols and hardware-enforced privacy guarantees.
01. ZERO RAW-DATA RETENTION
Incoming agent telemetry streams are processed strictly in-memory within isolated WebAssembly enclaves. Raw model parameters, unhashed prompts, and customer PII are never written to persistent disk storage.
02. MERKLE TREE ANONYMIZATION PROOFS
All state transitions produce deterministic SHA-256 Merkle tree proofs. Only anonymized, ZK-compressed root hashes are committed to public consensus layers.
State Proof = SHA256(JSON Payload + Timestamp + PKI Signature) 03. FIPS 140-3 LEVEL 3/4 HSM ENCLAVES
Cryptographic keys, root certificates, and micro-toll transaction signers reside inside FIPS 140-3 Level 3/4 Hardware Security Modules. Any physical or logical tamper attempt triggers immediate zeroization of Critical Security Parameters.
04. POST-QUANTUM DATA IN TRANSIT
Gateway mTLS enforces TLS 1.3 with Kyber-1024 hybrid post-quantum key exchange protocol across all edge ingress nodes.