hip-1194

HIP-1194: Trust — Trust Center and Evidence Controls. Status Final. Hanzo architectural specification.

HIP-1194: Trust — Trust Center and Evidence Controls

Abstract

/v1/trust is the canonical capability for trust within the Hanzo Cloud platform. Package trust is your trust centre: the controls you publish, the coverage they compute to, the documents a reviewer asks for, and who you send data to. The implementation is hanzoai/cloud apps/trust and plugin/trust (HIP-0106, HIP-0139). All operations are native, composable, and authenticated against Hanzo IAM (HIP-0026).

Motivation

Before this specification, trust operations lacked a unified canonical surface or were scattered across disparate endpoints. Under HIP-0139 (§1), every cloud capability maps 1:1 with exactly one plugin binary, one address prefix, one client class, and one authoritative specification. This eliminates duplicate implementations and ensures strict physical isolation, predictable billing, and orthogonal composability across the estate.

Specification

The key words MUST, MUST NOT, and SHOULD are to be interpreted as in RFC 2119.

§1 Addresses and Operations

The trust capability answers exclusively under its assigned route prefixes:

| Method | Path | Summary | |---|---|---| | GET | /v1/trust | Reads YOUR organization's whole trust centre, including the addresses of your own gated... | | GET | /v1/trust/controls | Lists every control your organization publishes, with the counts. | | GET | /v1/trust/controls/{id} | Reads one control by id. | | GET | /v1/trust/coverage | Reads coverage: per framework, how many clauses have an automated control behind them, ... | | GET | /v1/trust/coverage/{framework} | Reads one framework clause by clause: every clause the standard publishes, what covers ... | | GET | /v1/trust/documents | Lists your organization's documents. | | GET | /v1/trust/evidence | Reads the audit rows that stand behind one control, over a window. | | GET | /v1/trust/faq | Lists your knowledge base — the questions a reviewer asks, answered once. | | GET | /v1/trust/frameworks | Lists the frameworks coverage is computed against, and how many clauses each publishes. | | GET | /v1/trust/policies | Lists your organization's published policies. | | GET | /v1/trust/profile | Reads your organization's trust-centre profile — the name, tagline and summary a visito... | | GET | /v1/trust/published/{org} | Reads a published trust centre — the whole thing in one answer: the organization's prof... | | GET | /v1/trust/risk | Reads your risk profile — the label and value pairs describing what your organization h... | | GET | /v1/trust/subprocessors | Lists the third parties your organization sends data to, each naming what it is for. | | GET | /v1/trust/updates | Lists your trust-centre updates, newest as you ordered them. | | PUT | /v1/trust/{kind}/{id} | Writes one record into a section of YOUR organization's trust centre — profile, control... | | DELETE | /v1/trust/{kind}/{id} | Removes one record from a section of your organization's trust centre. |

§2 Storage and Physical Isolation

Data is isolated physically per organization using cloud.OrgDB: {DataDir}/orgs/{org}/trust.db. Isolation is strictly enforced at the filesystem and OS level; no cross-tenant queries are permitted. Where temporal or timeseries data is captured, postings are signed and immutably appended.

§3 Authentication and Principal

Every request reaching /v1/trust MUST present a valid Hanzo IAM bearer token (HIP-0026, HIP-0111). Anonymous requests are rejected at the edge gateway before invoking the plugin. The executing principal is extracted from the token and bound to the request context.

Security Considerations

  1. Physical Separation: Each tenant retains an isolated SQLite database file.
  2. Replay & Channel Binding: Direct dials and internal RPCs enforce channel binding over ZAP native transport.
  3. Audit Trails: All state-modifying actions emit immutable audit events to the centralized event plane (HIP-1190).

References