Entropa_

Trust & controls

What Entropa's architecture actually does, each claim backed by real code or a public document you can check yourself — not a certification, and not marked done unless it genuinely is.

Cryptography & integrity

Post-quantum signatures

Every checkpoint is signed with ML-DSA (NIST FIPS-204), independently verified against NIST's own published test vectors — not just "should be correct."

Tamper-evident, append-only log

Records are folded into a signed Merkle checkpoint. A later record can never rewrite an earlier one's proof.

Cryptographically checked, not just asserted

Every record page runs a real inclusion-proof and signature check and shows the actual result — not a claim taken on faith.

Data handling

Data-minimal by design

Entropa never receives your underlying data — only a hash you compute yourself, plus an optional short label you choose to disclose.

Per-customer isolation

Every customer gets their own private Merkle tree. Two customers' data can never physically occupy the same structure.

You're always in control of your data

Download your complete attestation history any time, with one click — nothing is ever locked away. If you ever choose to cancel, your tree and account record are deleted in full, so there's nothing left lingering afterward either.

Encrypted in transit

All API traffic is HTTPS/TLS. No plaintext submission path exists.

Access & operations

Per-account API key authentication

Every write is authenticated by a bearer key tied to your account. Identity comes from the key, never from anything the request body claims.

Least-privilege service accounts

Deploy, runtime, and admin roles are separate GCP service accounts, each scoped to only the permissions it actually needs.

Secrets never in source

Keys and credentials live in Secret Manager, never as literals in committed code — enforced by an automated secret-scanning gate on every commit.

Continuous dependency scanning

Every dependency is checked against known vulnerabilities on every push and on a daily schedule, not just at release time.

Governance & standards alignment

Maps to major regulations and frameworks

The signed, timestamped, tamper-evident log provides the specific recordkeeping/evidence component that BSA/FinCEN recordkeeping rules, SR 11-7 model risk management guidance, EU AI Act Article 12, NIST AI RMF, ISO/IEC 42001, and IAPP AIGP each call for — not a full compliance program or the regulation itself.

Adheres to HITRUST-informed controls

Entropa runs on Google Cloud's own HITRUST-assessed platform, and the application-layer controls Entropa owns directly (least-privilege IAM, no PII in the data path, secrets never logged) are built to that same bar as a default, not an afterthought. Stated honestly: not independently certified — adherence to the controls is the real, verifiable claim.

Real legal terms in effect

A real Terms of Service and Privacy Policy govern the Service today, built on well-established, industry-standard SaaS legal structures.

Real SLA, grounded in Google Cloud's own commitments

Entropa targets 99.95% monthly uptime — a direct pass-through of Google Cloud Run's own published SLA, not a number invented separately from it. See the full SLA.

This page will only ever mark something ✓ once it's real and checkable — never rounded up from a partial truth.