← Governance framework
Trust & Verification
KERI Operations and Key Management Policy
Key generation, rotation, custody and recovery rules for KERI AIDs operated by ImpactMiles.
- Version
- v1.0
- Effective
- 2026-07-19
- Last reviewed
- 2026-07-19
- Next review
- 2027-07-19
- Owner
- Chief Trust Officer
- Approver
- Trust & Verification Committee
Anchored by content hashissued 2026-07-29
Payload hash
bd9b27abd985b2985620db04232051019bde6e7c9f09afcc19812f706eec4b1eSHA-256 digest of the receipt content
Issuer AID
EP1_FGkcwfHAuih6VUzv9kgAVBvvSoaswSUao61lkxhEParty that issued this receipt
ImpactMiles handle
audit:governance:bd9b27abd985b298This receipt is anchored by content hash. A resolvable credential SAID is not available for this record.
Applies to
- Issuer AIDs
- Witness pool
- TAS operator credentials
Jurisdictions
- Hong Kong (PDPO, IRD s.88)
- United Kingdom (UK GDPR, DPA 2018)
- European Union (GDPR)
- Singapore (PDPA)
- Australia (Privacy Act 1988)
- Japan (APPI)
- Wider APAC per country taxonomy
How this is applied in-product
- TAS_API_KEY stored as a server secret, never client-side
- Rotation logged in the admin audit log
1. Custody
Issuer signing keys are held by the TAS operator under HSM-backed custody. ImpactMiles administrators hold delegated authority to trigger issuance but never possess signing material directly.
2. Rotation
- Scheduled rotation at least every 12 months.
- Immediate rotation on suspected compromise or personnel change.
- Every rotation event is anchored and referenced in the next issued credential.
3. Recovery
Multi-party recovery quorum documented in the operational runbook. Recovery drills conducted annually.
Questions or concerns about this policy? Contact the DPO.