← Governance framework
Trust & Verification

KERI Operations and Key Management Policy

Key generation, rotation, custody and recovery rules for KERI AIDs operated by ImpactMiles.

Version
v1.0
Effective
2026-07-19
Last reviewed
2026-07-19
Next review
2027-07-19
Owner
Chief Trust Officer
Approver
Trust & Verification Committee
Anchored by content hashissued 2026-07-29
Payload hash
bd9b27abd985b2985620db04232051019bde6e7c9f09afcc19812f706eec4b1e
SHA-256 digest of the receipt content
Issuer AID
EP1_FGkcwfHAuih6VUzv9kgAVBvvSoaswSUao61lkxhE
Party that issued this receipt
ImpactMiles handle
audit:governance:bd9b27abd985b298

This receipt is anchored by content hash. A resolvable credential SAID is not available for this record.

Applies to

  • Issuer AIDs
  • Witness pool
  • TAS operator credentials

Jurisdictions

  • Hong Kong (PDPO, IRD s.88)
  • United Kingdom (UK GDPR, DPA 2018)
  • European Union (GDPR)
  • Singapore (PDPA)
  • Australia (Privacy Act 1988)
  • Japan (APPI)
  • Wider APAC per country taxonomy

How this is applied in-product

  • TAS_API_KEY stored as a server secret, never client-side
  • Rotation logged in the admin audit log

1. Custody

Issuer signing keys are held by the TAS operator under HSM-backed custody. ImpactMiles administrators hold delegated authority to trigger issuance but never possess signing material directly.

2. Rotation

  • Scheduled rotation at least every 12 months.
  • Immediate rotation on suspected compromise or personnel change.
  • Every rotation event is anchored and referenced in the next issued credential.

3. Recovery

Multi-party recovery quorum documented in the operational runbook. Recovery drills conducted annually.

Questions or concerns about this policy? Contact the DPO.

Related policies