# Security and Trust Boundaries

URL: https://docs.nexart.io/docs/evidence-bridge/security

Exactly what Evidence Bridge proves and what it does not: transformation provenance and record integrity are cryptographic, producer claims about the world remain producer claims.

## What Evidence Bridge can prove

- which source bytes were received
- which canonical source JSON was mapped
- which mapping profile and revision was used
- which deterministic transformation was applied
- which CER was created
- that protected CER content has not been changed
- that the Node attested the same certificate identity
- that the Node receipt signature verifies
- that timestamp evidence verifies when TSA trust validation succeeds

## What Evidence Bridge cannot prove from source data

- that the source application told the truth
- that an externally reported action physically occurred
- that a model response was correct
- that an action was authorized
- that governance was valid
- that an operation was legally compliant
- that a producer identity is independently authenticated unless separate identity evidence exists
- that the execution caused the reported state change

NexArt proves integrity of captured execution evidence. It does not convert producer assertions into independently observed facts.

## Language rules

NexArt documentation says &quot;proves the integrity of the captured record&quot;, &quot;cryptographically binds&quot;, &quot;producer-reported&quot;, &quot;independently verifiable&quot;, &quot;Node-attested&quot; and &quot;confidential commitment&quot;. It avoids claims such as &quot;proves the event is true&quot;, &quot;proves the action definitely happened&quot;, &quot;proves the AI was correct&quot;, &quot;guarantees compliance&quot;, &quot;guarantees governance&quot; and &quot;immutable&quot;, where the accurate claim is tamper-evident or cryptographically verifiable.

## Privacy and storage

- profiles and evidence metadata are tenant-scoped
- raw source payloads are ephemeral by default
- confidential openings are stored separately and privately
- public CERs never contain openings

The production database and persistence architecture is implementation-specific and may change. Evidence Bridge does not promise a particular database or guarantee permanent storage of all profiles and results. See also Privacy and Data Handling.

## API key handling

The customer NexArt API key is request-scoped: not stored by Evidence Bridge, not returned to the browser, never logged. See Authentication and Key Management.

© 2025–2026 NexArt · Operated by Artnames Ltd, United Kingdom · hello@nexart.io
