Security & trust
This section describes the security controls FACE implements. It is written for the security reviewers, assessors and architects who have to decide whether FACE can hold their data.
Every page follows the same rule. It describes a control that exists in the code, names the setting, RPC or error text the control uses, and ends with what the control does not establish. If a property is not stated here, do not assume FACE has it. Ask us instead.
Design principles
- Fail closed at startup. FACE will not start without its mesh certificate authority, its at-rest key-encryption key, its session signing key, its encrypted application root and an inference endpoint. No fallback mode runs with any of these missing.
- No switch that turns a control off. Mesh mTLS, at-rest sealing and the instance-metadata refusal cannot be disabled by any environment variable.
- Sovereign inference. FACE calls no third-party LLM API. The text, vision and speech models run inside your own cluster.
- The lineage log records structure, never values. It records which source was read, what shape came back and where it went. It never records the data itself.
- Say what a control does not do. A green check is worth only what it actually proves.
Pages in this section
Where the platform ends and FACE begins
FACE is an application running on the Runink platform. The platform provides the
cluster, the edge that terminates browser TLS, certificate and secret delivery,
the object store and the inference plane. These pages describe what the FACE
backend enforces itself, together with the shared Runink libraries it links
(security, store, mesh and inference). Where a property depends on how the
platform is deployed, the page says so. Deployment and day-to-day operation are
covered in Operations.