Key material
- Provider signing keys mount from the host secrets directory and never touch the application database.
- Reads are contained to a configured base path. Symlinks rejected. Escapes refused.
- Master encryption key for at-rest secrets is pulled at boot, validated to 32 bytes, and never logged.