nexart.iodocs

    Security and Trust Boundaries

    Exactly what Evidence Bridge proves and what it does not: transformation provenance and record integrity are cryptographic, producer claims about the world remain producer claims.

    What Evidence Bridge can prove

    • which source bytes were received
    • which canonical source JSON was mapped
    • which mapping profile and revision was used
    • which deterministic transformation was applied
    • which CER was created
    • that protected CER content has not been changed
    • that the Node attested the same certificate identity
    • that the Node receipt signature verifies
    • that timestamp evidence verifies when TSA trust validation succeeds

    What Evidence Bridge cannot prove from source data

    • that the source application told the truth
    • that an externally reported action physically occurred
    • that a model response was correct
    • that an action was authorized
    • that governance was valid
    • that an operation was legally compliant
    • that a producer identity is independently authenticated unless separate identity evidence exists
    • that the execution caused the reported state change

    NexArt proves integrity of captured execution evidence. It does not convert producer assertions into independently observed facts.

    Language rules

    NexArt documentation says "proves the integrity of the captured record", "cryptographically binds", "producer-reported", "independently verifiable", "Node-attested" and "confidential commitment". It avoids claims such as "proves the event is true", "proves the action definitely happened", "proves the AI was correct", "guarantees compliance", "guarantees governance" and "immutable", where the accurate claim is tamper-evident or cryptographically verifiable.

    Privacy and storage

    • profiles and evidence metadata are tenant-scoped
    • raw source payloads are ephemeral by default
    • confidential openings are stored separately and privately
    • public CERs never contain openings

    The production database and persistence architecture is implementation-specific and may change. Evidence Bridge does not promise a particular database or guarantee permanent storage of all profiles and results. See also Privacy and Data Handling.

    API key handling

    The customer NexArt API key is request-scoped: not stored by Evidence Bridge, not returned to the browser, never logged. See Authentication and Key Management.

    © 2025–2026 NexArt · Operated by Artnames Ltd, United Kingdom · hello@nexart.io