Trust
Security
HTTPS · OAuth · confirmation · integrity · Verification Transparency.
CRYSTALIZE documents acquisition and integrity. It does not determine legal admissibility or evidentiary weight.
Controls
- ✓ HTTPS
- ✓ OAuth
- ✓ Preview + confirm
- ✓ Access control
- ✓ Tenant / owner isolation
- ✓ SHA-256 hashes
- ✓ Signatures
- ✓ Technical RFC 3161
- ✓ Signed download URLs
- ✓ Revocable access
- ✓ Audit (no secrets)
Verification Transparency (Why VERIFIED?)
When a package is VERIFIED, CRYSTALIZE can expose technical details such as:
- Package, manifest, and report SHA-256
- Manifest and report signature status
- Signed artifact binding
- RFC 3161 technical timestamp details (genTime, serial, policy OID, TSA fingerprint)
- Chain of custody events
- Package contents index
- Warnings and verifier / version
Qualified eIDAS timestamps are separate from technical RFC 3161 and are not claimed unless a qualified path is actually used.
Architecture boundary
ChatGPT→MCP / OAuth→CRYSTALIZE→
Capture→Evidence Package→Verify
Public integration host: api.crystalize.it (allowlisted routes). Capture engines are not exposed as open crawlers.
Signing keys
Public fingerprint for offline comparison: Signing keys. Private keys are never published.
Responsible disclosure
Email info@siriusdetector.com with subject [SECURITY]. Include reproduction steps; do not include customer secrets. PEC: intelsirius@pec.it.
What we do not do
- ❌ Autonomous internet crawling
- ❌ Capture without confirmation
- ❌ Bypass login / paywalls
- ❌ Decide legal admissibility