# Clavenar Security and Data Schedule

Version 1.0.0 · Vanteguard Labs LLC

## 1. Scope and evidence boundary

This schedule applies only through an executed Order Form. It states controls
Vanteguard will maintain for the selected Clavenar deployment. It does not
claim a certification, guarantee prevention of every incident, or expand the
deployment, service level, data class, or support commitment in the Order
Form.

## 2. Access, identity, and isolation

- Distinct authenticated workload identities and least-privilege route
  capabilities protect service-to-service access.
- Tenant identity is verified and carried through authorization, policy,
  approval, execution, evidence, retention, and deletion paths.
- Administrative access is limited to authorized personnel, uses individual
  identity and strong authentication, and is reviewed and revoked when no
  longer needed.
- Customer credentials and private keys are not accepted through general
  forms, source control, ordinary email, or support chat.

## 3. Customer-controlled secure exchange

Required secrets or production detail must use
`clavenar.customer-secure-exchange/v1` and the published local-only tool. The
customer:

1. creates and retains an X25519 private key;
2. verifies an order-specific Clavenar recipient key ID through an
   authenticated channel;
3. encrypts locally to distinct customer and Clavenar recipients with a
   maximum lifetime of 168 hours;
4. stores the envelope in a customer-controlled location and grants bounded
   access; and
5. revokes access and rotates exposed material after the transfer purpose ends.

The tool uses X25519, HKDF-SHA-256, and AES-256-GCM; binds creation and expiry,
both recipient roles, exact paths, byte sizes, and SHA-256 commitments; and
rejects symlinks, unsafe paths, excessive files/bytes, altered metadata,
substituted recipients, authentication failure, and expiry. It performs no
network request. Clavenar retains only order-approved content for the bounded
purpose and minimized commitments/lifecycle evidence afterward.

## 4. Product and infrastructure security

- Supported production paths fail closed when required identity, policy,
  approval, evidence, signing, or durable state dependencies are unavailable.
- Customer-selected agent actions pass through authenticated policy,
  human-approval where configured, bounded execution, and append-only
  cryptographic evidence boundaries.
- Release artifacts are built through protected workflows, inventoried,
  signed by immutable digest, and promoted through readiness and
  representative-transaction gates.
- Secrets and signing authority are separated from public source and ordinary
  application logs. Logs and receipts exclude bearer values and raw private
  keys.
- Dependency and vulnerability findings are triaged under the published
  security policy. Good-faith reports use the published coordinated disclosure
  channel.

## 5. Encryption and key management

Supported external transport uses TLS; governed workload transport uses
mutually authenticated workload identity. Sensitive retained application
payloads use authenticated encryption with purpose- and tenant-bound context.
Private workload and customer keys are not shared across identities. Key
creation, custody, rotation, revocation, and historical verification follow
the selected deployment’s documented procedures.

## 6. Availability, backup, and recovery

The selected topology, recovery objectives, maintenance, and service levels
must be stated in the Order Form. Scheduled backups capture the governed state
inventory into authenticated encrypted offsite objects and verify the written
object. Cold-passive synchronization copies encrypted state, not plaintext.
Recovery validation checks exact inventory, signatures, tenant erasure
dispositions, workload readiness, and a representative transaction before
service. These controls do not create a service level unless the Order Form
states one.

## 7. Incident response

Vanteguard maintains detection, containment, evidence preservation,
eradication, recovery, and review procedures. It will notify Customer without
undue delay after confirming a Personal Data Breach and targets an initial
notice within 24 hours of confirmation. Notice will use the security contacts
in the Order Form and provide known scope, affected data/systems, likely
impact, containment, and next update. The parties will coordinate legally
required notices; Customer controls notices for which it is controller.

Critical customer reports receive acknowledgement under the executed support
terms. Vanteguard may take the minimum necessary protective action, including
credential revocation or affected-path suspension, while preserving evidence
and communicating material status.

## 8. Retention, return, and deletion

The Order Form defines permitted data and any shorter lifecycle. On verified
request or termination, Vanteguard returns or deletes active Customer Data
within thirty days. Current tenant-erasure dispositions apply to older backups
before workload access so deleted tenant content is not resurrected. Backup
objects must age out within the Order Form schedule, no longer than 180 days
absent a documented legal hold. Legal holds are scoped, recorded, access
limited, and released when the duty ends.

Minimized commitments, security events, billing records, and legal evidence
may be retained for their documented purpose when they do not reconstruct
deleted Customer content. Customer revokes its access grants and manages
customer-controlled source copies and private keys.

## 9. Customer responsibilities

Customer classifies data, limits submitted content, uses supported clients,
protects identities and keys, reviews authorized users, configures approval and
policy appropriate to its risk, monitors its systems, maintains its recovery
obligations, and reports suspected incidents promptly. Customer does not
disable mandatory controls or treat Clavenar as a substitute for legal,
security, compliance, or human-oversight duties.

## 10. Assurance and changes

Vanteguard will provide scoped evidence reasonably necessary for procurement
and DPA audit under confidentiality, protecting other customers and security.
No customer receives another customer’s data, credentials, or topology.
Vanteguard will give reasonable notice of a material reduction in this
schedule during an active paid Order Form and will not apply the reduction
retroactively where prohibited by the agreement.
