Trust centre / Evidence index

Check the evidence.
Inspect the design.

Explore the public construction, verification tools and documented security controls. Use the evidence below to evaluate your deployment.

WHAT YOU CAN CHECK YOURSELF

Read the design.
Check the evidence.

An implementation, a certification and an independent audit answer different questions.

  1. 01Read what it protects

    Start with the design and its stated limits.

  2. 02Inspect the available evidence

    Check the scope of each test and certification.

  3. 03Run the verification tools

    Compare implementation behaviour with public reference examples.

Current status

Available evidence and planned reviews

The construction, source and test vectors are public for review. An independent cryptographic audit is planned and is not complete. Passing implementation checks is not an independent security audit or proof of security.

Cyber Essentials covers organisational security controls; it does not validate the cryptographic construction. SOC 2 examination and ISO 27001 certification remain on the roadmap, as detailed below.

Limits and scope

Decoys provide an alternative message, not a guarantee against coercion, legal compulsion or evidence from other sources. File metadata, access patterns and the surrounding context can distinguish messages. Keep real control files separate.

Tripwires observe matching inputs at supported deny.sh decrypt endpoints. Offline decryption and a fake credential tested directly with another provider are not automatically observed. Alert delivery and key rotation have no guaranteed timing.

Agent integrations depend on trusted code keeping real keys outside model-accessible context, tools, logs and errors. They do not prevent misuse of an authorised tool or compromise of the trusted runtime.

Hosted encryption receives messages and passwords during processing. Local browser and SDK encryption keep those inputs in your environment. BYOK revocation blocks future unwrapping, not copies already obtained.

Read the full threat model · Processing boundaries · Certification and review details

Operational boundaries

Hosting, handling and jurisdiction

What reaches our servers

Browser encryption and local code libraries (SDKs) keep inputs on your machine. Hosted encryption services (APIs) receive messages and passwords. Cloud vault storage receives encrypted content and metadata.

Surface-by-surface disclosure ↗

UK company and legal scope

deny.sh is operated by Treehouse in Valhalla Ltd, registered in England and Wales. Read the processing, legal and operational documents for the applicable boundaries.

Compliance and control evidence ↗

// certification

Certifications and review status

Distinguish current certification from documented controls and planned independent reviews.

Certified

Cyber Essentials

IASME, valid 15 May 2026 through 15 May 2027. Includes £25k cyber liability insurance via Sutcliffe & Co.

Verify on BlockMark →
Live

UK GDPR + DPA

Treehouse in Valhalla Ltd is the UK data controller. Privacy policy and DPA published, DPA incorporable into commercial contracts on request.

/dpa →
Roadmap

SOC 2 Type II

SOC 2 assesses organisational security controls. Our controls map uses TSC 2017 with 2022 Points of Focus. No independent SOC 2 examination is complete; dates will be announced once engaged.

Controls map →
Roadmap

ISO 27001:2022

ISO 27001 is an information-security management standard. Our Annex A mapping is internal documentation, not certification. No certification date is announced.

Controls map →

// security controls

Shipped engineering controls

Review the controls below, then check their scope and your plan’s availability in the linked documentation.

01 · live

Audit chain + signed receipts

Linked records make changes detectable. Signed receipts and RFC 3161 timestamps from a timestamp authority (TSA) support review of recorded activity, not every possible access.

03 · live

Durable usage metering

Per-tier daily metering with headers, dashboards, and 80 / 95 / 100 percent email alerts. Quota events join the audit chain (a linked, tamper-evident record of events).

04 · live

BYOK envelope (AWS KMS)

Server-stored ciphertext (the encrypted data) wrapped with a per-record data encryption key (DEK), itself protected by your customer-managed key (CMK) in AWS Key Management Service (KMS). Revocation blocks future unwrapping; it cannot recall copies already obtained.

05 · live

Pre-built integrations

Customer-side storage in AWS Secrets Manager, signed event notifications (webhooks), and company sign-in (SAML SSO) with accounts created at first sign-in (JIT provisioning).

06 · live

Compliance documents

This trust centre, the controls map (SOC 2 TSC and ISO 27001 Annex A), the lightweight status page, and the honest roadmap blog post.

// controls map

Controls map

Every SOC 2 Trust Services Criterion and every ISO 27001:2022 Annex A control mapped to the product feature or operational control that evidences it. Public index, with the deeper policy pack assembled under NDA on procurement engagement.

SOC 2 TSC 2017 with 2022 Points of Focus. CC1 governance · CC2 communication · CC3 risk assessment · CC4 monitoring · CC5 control activities · CC6 logical access (audit-chain, BYOK (bring your own encryption key), integrations controls) · CC7 system operations (audit-chain, metering, integrations controls) · CC8 change management · CC9 risk mitigation · A1 availability · C1 confidentiality (BYOK, integrations controls) · PI1 processing integrity (audit-chain control).

ISO/IEC 27001:2022 Annex A. A.5 organisational · A.6 people · A.7 physical · A.8 technological (mapped against the same engineering controls and policies).

UK GDPR. Lawful basis, retention, rights, international transfers documented at /privacy and /dpa.

Out of scope today. HIPAA, PCI DSS, FedRAMP. Talk to us if your use case requires a specific posture.

Full controls map →

// documents

Documents

Public documents for initial review. Draft legal documents require execution before becoming binding.

// verification

Verifiability

Read the code, check the build, ping the health endpoint, examine the audit chain.

Status: /status · Health: /api/health · Code: github.com/deny-sh-crypto · Build: /verify

Evaluating deny.sh for procurement?

Write to hello@deny.sh. Under NDA we share the full controls pack: SOC 2 control documentation, ISO 27001 Annex A mapping, vulnerability management policy, vendor list with locations and roles, incident response runbook, business continuity plan, and the data residency matrix per plan tier. Include your deadline.

For security findings, see /disclosure.