Lifecycle
Track key state and operational readiness.
VaultCore is a control-plane authorization service for key lifecycle state, signer-binding intent, deployment boundaries, and signing receipts. Separate execution-routing services resolve governed backend profiles; VaultCore preserves authorization evidence and Alloy never holds customer private keys.
VaultCore supports Alloy’s controlled-deployment story: cloud, private cloud, or bank infrastructure with explicit responsibility boundaries.
Track key state and operational readiness.
Check tenant, operation, and policy before signing.
Preserve evidence for review and replay.
Keep backend responsibility explicit across customer-controlled or approved provider paths.
Track creation, activation, rotation, suspension, and retirement state as customer-governed records.
Map which service, tenant, policy, and operation can request signing authority.
Missing tenant, policy, provider, or key state stops the workflow with a reason-coded receipt.
Signing requests can be reviewed later with authority, policy, and provider boundary intact.
Every route keeps Alloy's public story grounded in operating records, custody boundaries, and right-sized modules.
We will map the first workflow Alloy should stabilize, the custody boundary, and the modules that create evidence.
Prefer email? hello@alloy.build