docs / Administration

Security model

How NOLAPSE keeps certificate material safe.

  • Keys encrypted at rest — private keys and the CA root are encrypted with AES-256 envelope encryption, with the KEK kept outside the database (Vault / KMS supported)
  • mTLS — every agent authenticates with a client certificate
  • Hash-chained audit log — verifiable, tamper-evident, and exportable to a SIEM
  • No sub-processor ever receives a usable private key — ACME issuance transmits only the CSR
  • PDPA · data-residency — hosted in Thailand, on-premise supported

See the Terms and Privacy Policy for the full legal detail.