Cryptographic posture
Signed vendor attestation
A machine-verifiable statement of who we are — and what we are not. Orgs can file /attest.json instead of trusting a PDF that anyone could forge.
Not a SOC 2 certificate. It is an Ed25519-signed posture bound to doctrine version, origin, and public verify key.
01
What it binds
- Product name + doctrine version
- Hard boundaries: not a bank / not a money transmitter
- Certification honesty flags (SOC2 / pen-test / refs)
- Published verify key (SPKI)
- Deploy id when available
Verify: open /verify, paste payload + signature from attest.json, or POST /v1/receipts/verify.
https://banking.noetfield.com · v2.8 · operations@noetfield.com