Security & Compliance Overview

Maelstrom AI's transparent security program and ISO 27001:2022 ISMS, covering both platforms — Provii (zero-knowledge age verification) and downpipes (no-custody Cloudflare backup & disaster recovery)

Public

Our Security Philosophy

Maelstrom AI is built on a foundation of security by design and radical transparency. We believe that real security comes from sound cryptographic principles, defence in depth, and open scrutiny, not from hiding implementation details.

Our zero knowledge age verification service is designed to verify age without requiring Maelstrom AI-operated services to collect or store any personally identifiable information (PII). This isn’t just a privacy feature; it’s our entire security model.

What We Protect

Maelstrom AI operates two platforms under one ISMS — Provii (zero-knowledge age verification) and downpipes (no-custody backup & disaster recovery for the Cloudflare data layer). Our security program focuses on protecting:

  1. Cryptographic integrity - Sound proofs (Provii) and verifiable, tamper-evident archives (downpipes)
  2. Service availability - Maintaining uptime and, for downpipes, proven recoverability
  3. Credential & key security - Protecting signing keys and credential issuance (Provii); the customer holds their own encryption keys under a no-custody model (downpipes)
  4. Operational security - Securing development, deployment, and operational infrastructure
  5. Supply chain security - Ensuring the artifacts you download, and the engine updates you apply, haven’t been tampered with

For Provii, our operational services minimise PII processing (DOB is processed ephemerally during issuance only and never persisted). For downpipes, the no-custody architecture means Maelstrom never holds customer keys or data: backups run in the customer’s own Cloudflare account, sealed under the customer’s keys.

Our ISMS Scope

Organisation: Maelstrom AI Pty Ltd ATF Maelstrom AI Holding Trust

Service: Design, development, deployment, operation, maintenance, and support of Maelstrom AI’s two platforms — the Provii zero-knowledge age-verification platform and the downpipes no-custody backup & disaster-recovery platform. See the ISMS Scope Statement for the full system boundary and the shared-responsibility model.

Infrastructure:

  • Cloudflare Workers (edge computing)
  • Cloudflare KV & Durable Objects (state management)
  • Cloudflare R2 (backup destinations and the signature-pinned downpipes update channel)
  • GitHub (source control, CI/CD)
  • Cloudflare Workers Assets (static site serving)
  • The downpipes vendor-side control-plane (licence tokens and a content-free advisory beacon; holds no customer keys, data or Cloudflare tokens)

Data Handling:

  • PII. During credential issuance, a date of birth is transmitted to the issuer API where a Pedersen commitment is computed server-side; the raw DOB is immediately discarded and never persisted to storage. During age verification, no personal information is collected or transmitted.
  • IP Addresses. Retained for 90 days in audit logs for anti-abuse and diagnostics. Standard audit log entries are retained for 90 days. Critical security events (such as detected attacks, replay attempts, and IP blocks) are retained for up to 365 days to support security investigation.
  • Cryptographic Proofs. Ephemeral verification, no long-term storage

Security Program Structure

Our Information Security Management System (ISMS) comprises:

Key Security Features

Zero knowledge Architecture

Our Groth16 zero knowledge proofs are designed so that age verification happens without revealing any personal information. See the trust model for details.

Supply Chain Security

Our supply chain targets SLSA Level 3 provenance with:

  • Hermetic builds on ephemeral infrastructure
  • Cryptographic signing via Sigstore
  • Non-falsifiable provenance attestations
  • Transparency logging in Rekor

Edge Security

Cloudflare Workers provide:

  • Global DDoS protection
  • Edge-based rate limiting
  • Automatic TLS termination
  • Isolated execution environments

Cryptographic Assurance

Our cryptography stack includes:

  • Groth16 proofs on BLS12-381 curve
  • RedJubjub signatures for credential issuance
  • BLAKE2/SHA256 for hashing and commitments
  • Battle-tested libraries: bellman, bls12_381, jubjub

See provii-crypto for implementation details.

Regulatory Compliance

Australian Privacy Act 1988: Our zero knowledge architecture minimises personal information processing. DOB is processed ephemerally during issuance only, significantly simplifying compliance obligations.

GDPR Considerations: While not directly subject to GDPR (no EU establishment or EU data processing), our architecture would provide strong privacy protection for EU users through data minimisation.

Transparency Principles

This entire ISMS is public because:

  1. We have nothing to hide - Minimal PII processing means minimal sensitive data to protect through obscurity
  2. Open scrutiny improves security - Public review helps identify weaknesses
  3. Trust through verification - You can verify our claims by reviewing our code and processes
  4. Industry leadership - We want to set an example for privacy-preserving services

Getting Started

Understand our scope

Review the ISMS Scope Statement to understand what’s covered

Review security controls

See the Statement of Applicability for how we implement ISO 27001 controls

Check operational procedures

Verify our security

Use our artifact verification guide to cryptographically verify the software you download

Security Contact

Security Issues: For responsible disclosure of security vulnerabilities, email security@maelstrom.au (private, confidential)

General Questions: Open a discussion on GitHub Discussions


Document Information

  • Version. 1.2
  • Last Updated. 2026-06-16
  • Owner. ISMS Owner
  • Review Frequency. Annually
  • Classification. Public