Docs

Security

Private keys stay in cloud HSM custody. The Mac holds public certs and device credentials only.

Private keys remain in cloud custody

HSM and database access stay behind Liminal. Console and the Mac agent never receive private key bytes.

Console overview with cloud custody posture

Custody

Signing private keys are created and used inside a cloud HSM. The product path does not export private keys to administrators, the Console UI, or the Mac agent as downloadable key material.

What the Mac holds

What Console holds

Authorization model

Each sign is authorized only by applied, enabled policy rules for that tenant. A match requires identity, subject (user and/or group and/or device), operation (sign), and optional validity window. Missing context or no matching rule refuses the sign. Rules that require confirmation withhold the signature until the Mac user approves.

Transport and identity

Production API and Console are served over HTTPS on liminalkeys.com hostnames. Console authentication uses organization directory SSO (Microsoft work account). Device enrollment uses short-lived codes issued by an authorized Console user.

Hard limits

← macOS agent · All docs