Status-aware index of implemented controls, evidence templates, external controls, and roadmap items.
Managed Platform Trust Documentation Index
This index maps KMP’s managed multi-tenant trust material and its current publication status. It is not itself assurance evidence. Every external statement requires customer-safe language, current environment evidence, and the listed review. Published pages must not expose secrets, signed object URLs, raw logs, privileged implementation details, tenant-private data, or another tenant’s identifiers.
Current: implemented in the repository; verify the deployed environment before publishing.
Conditional: available only when configured and evidenced.
External prerequisite: not supplied by the active Azure application/infrastructure path.
Roadmap/template: planned behavior or an evidence-gathering aid, not a completed control.
Current platform qualifications
Architecture and tenant isolation currently use a separate PostgreSQL database per tenant plus a platform database.
Document isolation is logical by tenant container/prefix. The current managed identity has storage-account-wide Storage Blob Data Contributor access.
The active Azure Bicep is single-region; regional recovery remains an external prerequisite.
One global backup policy supports daily/weekly cadence and defaults to daily/30 days. Managed jobs run tenant fleet backups; platform backups may be explicitly requested. Tenant artifacts are .json.gz.enc and platform artifacts are .pgdump.enc.
The database audit hash chain exists. The Azure WORM sink is not implemented, defaults disabled, and requires an external immutable destination.
The Shamir KEK helper is a non-production placeholder; the production escrow ceremony is external.
Platform Admin is part of the same web app on reserved hosts. It uses in-app password plus TOTP, lockout, account status, and host-bound sessions, and it includes mutating operations.
Tenant trust and public status routes are roadmap.
Internal decision template; publish only an approved high-level status
Platform Owner
Customer-safe publication rules
Describe only controls and outcomes supported by current evidence; mark unperformed work as required, external, or roadmap.
Never state that a penetration test, DR drill, restore drill, escrow ceremony, external audit, or WORM control is complete until its approved evidence package exists.
Explain the difference between separate tenant databases, logical document boundaries, and the cloud identity’s account-wide storage role.
State the deployed region and tested recovery posture. A runbook or geo-redundant service option does not prove regional failover.
Publish the actual configured backup cadence/retention and tested artifacts, not governance placeholders.
Describe Platform Admin as privileged and mutating; do not call it a separate application, externally authenticated, or read-only.
Link to counsel-approved terms for contractual commitments.
Include WCAG 2.2 AA evidence for any customer-facing trust or status interface once those roadmap routes are implemented.
Required trust packet before a production commitment