Event Vault uses Role-Based Access Control (RBAC) as its foundational security layer, allowing for granular denition of roles and policy-driven workows. Trustees can be assigned more than one role, but each active role in your vault setup must have at least one trustee.
●Validation Trustees (Constituting your "Trust Circle"):
- Role: These are the gatekeepers of your vault. Their primary responsibility is to independently conrm that the specic real-world trigger event you dened for vault access has actually occurred.
- Process: When an Open Vault Request (OVR) is made, all Validation Trustees must unanimously approve it before the process to access the vault contents can proceed.
- Notifications: All parties involved, including other trustees, are informed of OVRs and trigger details, enhancing transparency.
- Role: These trustees (or the Data Owner themselves) are designated to hold a copy of the encrypted vault contents (the Encrypted Digital Data Set - DDS).
- Security: The DDS is encrypted and distributed; it is never stored centrally on our main plaorm servers.
- Access: File Holder Trustees cannot decrypt the vault contents themselves unless they are also designated as Key Holders within a specic access policy. Their role is part of our "digital router" system that decouples data, keys, and metadata
- Role: Key Holder Trustees are individuals authorized by your vault's policy to be part of the workow that receives or enables access to the decryption keys aer all conditions, including unanimous Validation Trustee approval, have been met.
- Security: Decryption keys are generated in a secure enclave and managed by an external Key Management System (AWS KMS). Our plaorm does not host or directly access these keys.
- Process: Access to keys is governed by the RBAC policies you dene and the successful completion of all required validation steps.
By understanding these roles and principles, you can condently select trustees who will help ensure your digital information is shared securely, conditionally, and exactly when needed, according to your plan.