Documentation
Start with the architecture pillar you care about. Operational documentation for a workspace lives inside the signed-in application, where it can be scoped to your tenant and your permissions.
The architecture, one pillar at a time.
Each of these pages is the public reference for a pillar of the control plane, and the mechanism behind each one.
Presence Sessions
The session object, its lifecycle, the eleven portal states, and the service objectives it operates within.
Read moreEdge fusion and portals
Secure channel ingestion, the non-blocking inference loop, tailgate detection, and the degraded-sensor matrix.
Read moreEndpoint agents
The desktop liveness state machine, liveness signal weights, and the macOS and Windows integration points.
Read morePolicy and toggleability
The evaluation model, the modality ladder, threat classes, and dual-control floor enforcement.
Read moreRevocation topology
Epoch fencing, the two-bus design, the offboarding sequence, and the latency budget.
Read moreIdentity and attestation
Directory binding, card issuance on your own equipment, and privacy-preserving employment verification.
Read moreSecret custody
The custody model behind Vault: password-derived keys, per-member wraps, and why an administrator cannot read a body.
Read moreCryptography and privacy
The drop pipeline, the encryption envelope, key custody, and how subject rights resolve.
Read moreConnectors
The shared connector contract, and what each connector brings in.
Read moreWhere each kind of documentation lives.
Public pages describe the architecture. Anything tenant-specific is behind authentication, because it describes your estate.
| You are looking for | Where it is | Access |
|---|---|---|
| How a pillar works | These public reference pages | Open to anyone |
| Implementation sequencing | The guides page | Open to anyone |
| What changed recently | The release notes page | Open to anyone |
| Operating your workspace | Knowledge spaces inside the application | Signed in, scoped to your permissions |
| Your connector configuration | Integration settings in the application | Signed in, administrator |
| Deployment and commissioning | Provided with your engagement | Under agreement |
| Interface specifications | Provided with your engagement | Under agreement |
What this site deliberately does not publish.
Threshold values, model identifiers, key derivation parameters, and portal commissioning procedures are not published here. They are shared under agreement with customers and their assessors, because publishing them helps an attacker more than it helps a buyer.
Everything on these public pages is written to be argued with by a security team. If a claim here does not match what you are shown in a technical session, we would rather hear about it than have you assume the marketing copy was the accurate version.
Who to write to.
Would you rather be walked through it?
A technical session covers the drop pipeline, a compiled policy pack, and a live revocation. It is more useful than any page on this site.