Skip to content

The switchboard

Every external dependency is a switch

Exedra Gate's externally connected capabilities are built behind seams: a common interface, named adapters, a configured selection. Each such capability is a switch a client can have set to off, supplied by the client, or operated by Exedra Gate. The point of building it this way is honesty under configuration: every position of every switch has a stated consequence for what the record can claim, in writing, before anything runs. A capability switched away from Exedra Gate's operated service is a claim the client takes over, not a claim that disappears.

Sovereign extension states are visible to workspace owners and admins in the audit console at /app/admin/audit, under the sovereign extensions tab.

Mail

Operated by Exedra Gate, outbound messages ride the platform's delivery provider and delivery events are recorded into the evidence trail by provider webhook. On the client's own mail infrastructure, the delivery-evidence claim is downgraded in writing: the record shows dispatch, recorded and timestamped, and evidence of delivery becomes the client's mail system's own. Switched off, counterparties are reached through the portal alone and the record says exactly that.

Identity verification

Operated by Exedra Gate, hosted verification runs through the platform's identity provider, and identity documents transit that provider's infrastructure. Supplied by the client, an adapter is built against the client's own identity vendor. Switched off, the client's verification process runs outside the platform and the platform records the outcome the client attests. The consequence travels with the switch: with it off, a verified badge reads as verified by the operator of that deployment's own process, never as verified by Exedra Gate. The attestation still signs; the attested statement changes.

Screening

Sanctions and adverse-media screening follows the same pattern. Operated by Exedra Gate, the client accepts that directors' and owners' special-category data leaves the perimeter for the check. In client mode or off, the client's own compliance function screens, the platform stores their resolution as a dated evidence event, and Exedra Gate issues no screening badge; an equivalent certification, if wanted, is the client's own. In every mode, screening surfaces information and a human reviewer decides. The software never approves, rejects or scores anyone.

Signing delegation

By default, evidence packs are signed with the platform-held Ed25519 key. A client can instead delegate signing to an endpoint they operate, so the private key never exists on the platform. The delegated path is strict by construction: the returned signature is verified against the client's pinned public key before it is accepted, a quiet key rotation is refused even if the signature would verify, a hung endpoint times out, and a failed delegated signature never falls back to the platform key; the pack is simply not produced. The claim consequence: key custody and key management assurance become the client's, under their controls and audit, and the platform's attestation covers the event chain, the pack hash and which key identifier signed.

Independent timestamping

The timestamp is the switch the whole claim ladder hangs on, and it has four postures. Connected, the default: a SHA-256 fingerprint is sent to an authority Exedra Gate designates, the independent-time claim holds in full, and that authority is independent of Exedra Gate, which is not itself a qualified trust service provider. Client-procured qualified authority: the hashes go to the client's own trust service provider, keeping the qualified timestamp's legal presumption inside the client's own contractual chain. On site: timestamps are issued inside the perimeter, nothing leaves, and the record is described as internally timestamped, never as independently timestamped. Off: packs remain signed and hash chained, and the claim ladder stops at integrity and order, dated by the operator's own clocks. Each downgrade is recorded in writing, because a client who chooses isolation should know exactly what was given up.

What survives every configuration

In every posture: the in-house signing engine with no third-party e-signature vendor in the path, per-document and per-person access control with row-level tenant isolation, the hash-chained audit trail, and evidence artefacts in standard formats that are checkable offline with free standard tools. And in every posture the same boundary holds: Exedra Gate sells software. It does not hold, route or settle funds, does not rank or recommend offerings, and takes no share of any raise.