SECURITY & LIMITATIONS
Security model
Designed to keep signing authority offline and verification input on the visitor’s device.
Key custody
The Enkiel Root CA private key remains offline. Signing keys are used by a separate local tool. The public website publishes only public certificates and metadata.
Local file processing
The current verifier parses a detached CMS signature and checks its file digest and cryptographic signature in your browser. The selected files are not uploaded. It downloads the pinned public Root CA certificate and a public DER CRL for certificate path and revocation checks. File processing is limited to 32 MiB for the original file and 1 MiB for the signature.
Trust limitations
A cryptographic signature, certificate validity, revocation status, identity trust, and trusted timestamp are different claims. A fresh CRL signed by the pinned Enkiel Root CA can show that a directly issued certificate is not listed as revoked at the CRL update time. Missing, invalid, or stale revocation evidence remains unknown. Enkiel is self-managed; a valid chain does not mean a third-party CA verified the person’s identity. Confirm the Root CA fingerprint out of band.
Responsible disclosure
Security contact details will be published here before production verification is enabled.
Contact process pending