docs / Administration
Security model
How NOLAPSE keeps certificate material safe.
- Keys encrypted at rest — private keys and the CA root are encrypted with AES-256 envelope encryption, with the KEK kept outside the database (Vault / KMS supported)
- mTLS — every agent authenticates with a client certificate
- Hash-chained audit log — verifiable, tamper-evident, and exportable to a SIEM
- No sub-processor ever receives a usable private key — ACME issuance transmits only the CSR
- PDPA · data-residency — hosted in Thailand, on-premise supported
See the Terms and Privacy Policy for the full legal detail.