Skip to content
Security & trust

Security & trust

This section describes the security controls FACE implements. It is written for the security reviewers, assessors and architects who have to decide whether FACE can hold their data.

Every page follows the same rule. It describes a control that exists in the code, names the setting, RPC or error text the control uses, and ends with what the control does not establish. If a property is not stated here, do not assume FACE has it. Ask us instead.

FACE is SOC 2-oriented in its design. These pages do not claim any certification, attestation or authorisation: SOC 2, ISO 27001, ISO 42001, FedRAMP, CMMC or ITAR. See Compliance posture for what that wording means and what it does not.

Design principles

  • Fail closed at startup. FACE will not start without its mesh certificate authority, its at-rest key-encryption key, its session signing key, its encrypted application root and an inference endpoint. No fallback mode runs with any of these missing.
  • No switch that turns a control off. Mesh mTLS, at-rest sealing and the instance-metadata refusal cannot be disabled by any environment variable.
  • Sovereign inference. FACE calls no third-party LLM API. The text, vision and speech models run inside your own cluster.
  • The lineage log records structure, never values. It records which source was read, what shape came back and where it went. It never records the data itself.
  • Say what a control does not do. A green check is worth only what it actually proves.

Pages in this section

Where the platform ends and FACE begins

FACE is an application running on the Runink platform. The platform provides the cluster, the edge that terminates browser TLS, certificate and secret delivery, the object store and the inference plane. These pages describe what the FACE backend enforces itself, together with the shared Runink libraries it links (security, store, mesh and inference). Where a property depends on how the platform is deployed, the page says so. Deployment and day-to-day operation are covered in Operations.

What this section does not establish. It describes the code. It is not a penetration test or an audit report, and it says nothing about the deployment you run. Network policy, log retention, key custody and backups all belong to your installation, and you have to verify them there.