HX-Provenance appliance security
The documented HX-Provenance Private Appliance includes signed release manifests, offline verification and a validation harness that the customer security team can run independently. Its release dossier identifies the supplied version and supporting security artifacts.
Offline evidence checks
The local verifier checks receipts and evidence bundles without a network connection or a HolonomiX endpoint. Verification uses the matching tool, complete evidence and expected issuer public key; retaining those materials supports checks after an outage or issuer change.
Read offline verification instructions
Customer key custody
For the documented HX-Provenance Private Appliance, signing keys are generated on the appliance at first boot, stored under customer-controlled permissions and retained in the customer environment. Receipt persistence and the storage backend are also customer-controlled.
HX-AEIR uses deliberate customer initialization instead of first-boot generation; the product matrix above preserves that distinction.
Air-gapped deployment
The documented HX-Provenance appliance supports customer-controlled air-gapped deployment without outbound connectivity. Its signed-JWT license can be installed, verified and rotated offline.
Review the appliance deployment boundary
Signed release manifest
Every shipped file in the documented HX-Provenance appliance release is hashed, and the manifest is signed with an offline release key. The appliance checks its manifest at first boot and refuses to start if verification fails.
Customer-runnable validation harness
The HX-Provenance release-blocking validation script covers fourteen gates, including DNS and TLS posture, health, the authentication boundary, public verification, receipt issuance and verification, tamper rejection, schema compatibility, bundle export, workspace quota, rate limiting, persistence, backup status and metrics. The customer security team can run the supplied harness independently.
Release dossier
The documented HX-Provenance release dossier includes a CycloneDX SBOM, vulnerability scan report, build provenance, validation summary, signed release attestation and offline verification instructions. These are product-specific delivery commitments; the dossier and validation results apply to the supplied release.
Read the delivery specification · Request the release dossier