Architecture principles
Reduce exposure before adding cryptography.
Public safe projection
Public routes return a deliberately limited record shape instead of serialising private workspace objects.
Server side authorization
Protected workspace routes validate the user token, workspace membership and write role for each request.
Hashed device secrets
The paired device token is returned once. The stored server value is a hash.
Signed event validation
Simulator ingestion checks the canonical payload hash and Ed25519 signature before acceptance.
Continuity and replay checks
Accepted event hashes cannot be replayed and previous event continuity is enforced.
Truth state labelling
Preview, draft, simulator and planned states remain distinct from final verification.
Verifier API
Unknown and private records share one response.
Public resolver behaviour
- Only approved public preview fields are projected
- Internal workspace identifiers are not returned
- Raw evidence and raw manifests are not returned
- Inactive record existence is not disclosed
Device interface reference
Validate the device and the signed payload.
Pairing and revocation
Short lived codes pair a simulator device. Revocation blocks future sessions and ingestion.
Signature and chain checks
Canonical hash, Ed25519 signature, replay state and previous event continuity are checked.
Creator permissions
Recording scope, permissions and device setup are explained in the Mac app workflow.
Privacy by boundary
Keep creative source material outside evidence collection.
Excluded evidence categories
- Source audio, video, stems and masters
- Creative project files and private folder contents
- Raw keystroke text, passwords and lyrics
- Prompts, scripts and private typed content
- Screenshots and screen recordings
- Raw file names and local paths
AI review controls
Separate analysis permission from recording permission.
An analyst with no control tools
The verification agent is designed to read authorised evidence. It must not operate creative software, browse private files or change original records.
References and review
Findings must refer to the evidence examined and retain their method and version. Model output alone cannot confirm an incident or impose a penalty.
Limited processing scope
The intended analysis input uses permitted aggregates and opaque references. Source media, typed content, names, local paths and account email do not belong in model requests.
Availability and contractual evidence
The public v1 API does not expose AI processing. Confirm provider, region, retention, deletion and operational terms for the actual service before approving a wider integration.
Engineering references
Use established engineering references.
API threat modelling is informed by the OWASP API Security Top 10. Secure development planning can also draw on the NIST Secure Software Development Framework. These are design references only. DigiBridge does not claim OWASP or NIST certification.
Authorize at the object boundary
Validate both the caller and the workspace, asset, project, session or device they are attempting to access.
Minimise public responses
Return a dedicated public schema instead of removing a few fields from an internal object.
Fail without disclosure
Use the same inactive response for unknown and intentionally private public identifiers.
Preserve response meaning
Display the status and verification fields returned by the endpoint alongside the relevant record.
Integration review
Agree the requirements for your integration.
Questions for your security review
- Which security evidence does your procurement process require?
- Does the integration need organisation credentials or only public lookup?
- What request volume and service expectations need an agreement?
- Which tool versions and recording permissions does your workflow use?
- How will your interface display current publication and verification status?
- Who can review disputed findings and record corrections?