# Security and Encryption Notice

**Version:** 1.2.4  
**Effective date:** July 27, 2026

Locked projects and Continuity packages use authenticated encryption. Credentials and tokens use operating-system-protected storage when available. Signed update, Threat Ledger, activation, and Marketplace data is verified before use. These controls reduce risk but cannot protect a compromised device, operating-system account, administrator, running process, provider account, recipient, printer spool, screenshot, clipboard, or unlocked document.

Losing every valid project key or recovery path can permanently prevent access. Maintain encrypted backups and test recovery. Report suspected vulnerabilities to **cbusinessact@proton.me**.


## Marketplace service isolation

The Vantage Marketplace publisher is designed to use a Vantage-only private Backblaze bucket, a bucket-and-prefix-restricted application key, Vantage-prefixed Cloudflare secrets, dedicated `/marketplace/` routes, a separate HMAC publisher secret, and signed JSON-only content. It does not use Pace Addon Shop sessions, owner claims, object paths, bucket, or application key.
