Docs
Security
Private keys remain in cloud custody
HSM and database access stay behind Liminal. Console and the Mac agent never receive private key bytes.
Custody
Signing private keys are created and used inside a cloud HSM. The product path does not export private keys to administrators, the Console UI, or the Mac agent as downloadable key material.
What the Mac holds
- Public certificate(s) for virtual identities
- Device credential from enrollment (protect like a password)
- Operational state for CryptoTokenKit (no private key bytes)
What Console holds
- Tenant and identity metadata
- Policy configuration (rules, confirmation flags, validity windows)
- Device enrollment state
- Sign audit records without digests, signatures, or key material
Authorization model
Each sign is authorized only by applied, enabled policy rules for that tenant. A match requires identity, subject (user and/or group and/or device), operation (sign), and optional validity window. Missing context or no matching rule refuses the sign. Rules that require confirmation withhold the signature until the Mac user approves.
Transport and identity
Production API and Console are served over HTTPS on liminalkeys.com hostnames. Console authentication uses organization directory SSO (Microsoft work account). Device enrollment uses short-lived codes issued by an authorized Console user.
Hard limits
- No DYLD insertion into Apple platform binaries
- CryptoTokenKit is the supported Mac integration surface
- Marketing pages never request or display secrets
- Audit never stores digests, signatures, or private key bytes