Proven integrity
- Tamper-evident history — a signed hash chain back to the very first entry. One flipped byte, caught.
- Encrypted at rest — AES-256-GCM. The host can’t read your code.
- Zero-knowledge — we can’t read your packages, or even the names of the ones you use. Nothing decrypted ever leaves your machine.
- Passwordless — your key is your identity. No passwords to leak, no IAM to manage.