| Compute | Per-tenant Intel TDX confidential enclave | Live |
| Verification | DCAP attestation + MRTD pinning endpoint | Live |
| AI | Attested NVIDIA GPU TEE inference, dual-attested | Live |
| Crypto in transit | TLS 1.3 every hop, auto-renewed certs | Live |
| Crypto at rest | AES-256-GCM, enclave Postgres + backups | Live |
| Envelopes | X25519 + HKDF + AES-256-GCM, HMAC-SHA256 | Live |
| Key custody | BYOK / CMK, dual-key rotation, fingerprint only | Available |
| Supply chain | Cosign + Rekor + SBOM + SLSA, reproducible | Live |
| Build gate | Fail-closed on HIGH/CRITICAL CVE | Live |
| Isolation | Kernel RLS (Postgres 16) + tenant salting | Live |
| Authority | RBAC + egress allowlist + kill-switch | Live |
| Evidence | WORM audit + non-PII runtime receipts | Live |
| Ingest | First-party ingest + dead-letter quarantine | Live |
| Agents | Agent-interaction control (AEO) at ingest | Live |
| Signal coverage | Classify-before-scoring governance gate | Live |
| Service auth | Hardened worker auth, no shared static secrets | Live |
| Activation | In-enclave CRM dispatch, your credentials | Available |
| Ad feedback | Closed-loop conversion value, hashed in-enclave | Available |
| Benchmarks | k-anon + l-diversity + differential privacy gates | Live |
| Verification | Trust Center + public verifier + evidence room | Live |
| Observability | RUM + readiness, Splunk / Datadog integrations | Live |
| Crypto tier | Rust / WASM defense-in-depth crypto module | Live |
| Governance | Master-graph change gate | Live |
| Assurance | Formal / property-based verification | In progress |
| Identity | SAML SSO + SCIM provisioning | Available |
| Compliance | Controls mapped, GDPR DPA, RTBF, IR SLA | In progress |